Executive brief
Dell Secure Connect Gateway is a remote access appliance and application used to secure network connections and gateway traffic. An attacker with remote access could exploit a hard-coded cryptographic key to bypass security protections and gain unauthorized access to the system or intercept protected traffic.
Technical details
The vulnerability is a use of hard-coded cryptographic key in Dell SCG 5.0 Appliance and Application versions. A low-privileged attacker with network access to the affected system could exploit this flaw by using the embedded cryptographic key to decrypt protected data, forge authentication tokens, or bypass encryption protections. The issue affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Dell has released patched versions that remove or randomize the hard-coded cryptographic material. Immediate patching is strongly recommended as the key material may be reversible from binary analysis.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16 and 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed