ZeroHour

CVE-2026-80134

large

Hard-coded Credentials in Dell Secure Connect Gateway 5.0 Enable Unauthorized Access

CVSS 3.1
7.7 high
EPSS
<1%p18
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00 contain hard-coded credentials (CWE-798), allowing an unauthenticated attacker who can reach the service over the network to gain unauthorized access to the affected system. The flaw is triggered remotely without valid credentials or user interaction, although the CVSS attack complexity is rated high, meaning successful exploitation may depend on conditions in the target environment. A successful attacker gains unauthorized access with high potential impact to confidentiality and integrity and low impact to availability (CVSS 7.7, High). Any organization running an affected SCG 5.0 Appliance or Application build, typically deployed as the secure remote-support gateway for Dell infrastructure, is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade the SCG 5.0 Appliance to 5.36.00.16 or later and the SCG 5.0 Application to 5.36.00.00 or later, following Dell's security advisory. Until patched, restrict network access to the SCG interface to trusted management networks, and monitor authentication logs for unexpected logins because embedded hard-coded credentials cannot be rotated by administrators.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
large~10,000-100,000 deployments at customer sites (rough estimate) — SCG 5.0 is Dell's remote-support connectivity appliance/application typically deployed once per customer environment where secure connectivity to Dell support services is required, but no public install counts or internet-scan data are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.