Executive brief
Dell Secure Connect Gateway (SCG) is a critical appliance and application used to manage secure remote access to corporate networks. A hard-coded cryptographic key vulnerability in versions prior to 5.36 allows unauthenticated attackers with network access to decrypt sensitive communications and bypass encryption protections, potentially exposing customer data and enabling unauthorized system access.
Technical details
The vulnerability is a use of hard-coded cryptographic key (CWE-321) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. An unauthenticated attacker with network reachability to the device can exploit this flaw by leveraging the embedded cryptographic key to decrypt sensitive data or forge valid authentication tokens. The attack requires no user interaction or authentication. Dell has released patches in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to address this vulnerability.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed