CVE-2026-80134
largeHard-coded Credentials in Dell Secure Connect Gateway 5.0 Enable Unauthorized Access
Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00 contain hard-coded credentials (CWE-798), allowing an unauthenticated attacker who can reach the service over the network to gain unauthorized access to the affected system. The flaw is triggered remotely without valid credentials or user interaction, although the CVSS attack complexity is rated high, meaning successful exploitation may depend on conditions in the target environment. A successful attacker gains unauthorized access with high potential impact to confidentiality and integrity and low impact to availability (CVSS 7.7, High). Any organization running an affected SCG 5.0 Appliance or Application build, typically deployed as the secure remote-support gateway for Dell infrastructure, is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.
What to do: Upgrade the SCG 5.0 Appliance to 5.36.00.16 or later and the SCG 5.0 Application to 5.36.00.00 or later, following Dell's security advisory. Until patched, restrict network access to the SCG interface to trusted management networks, and monitor authentication logs for unexpected logins because embedded hard-coded credentials cannot be rotated by administrators.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.