Junglewise Threat Intelligence

CVE-2026-78487: Dell Secure Connect Gateway hard-coded cryptographic key vulnerability

CVE-2026-78487 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) 5.0, used to secure remote connections and gateway access in enterprise environments, contains a hard-coded cryptographic key vulnerability. An attacker with local access could exploit this flaw to decrypt sensitive communications and access protected data, compromising the security of the entire gateway system.

Technical details

The vulnerability is a use of hard-coded cryptographic key in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. A low-privileged attacker with local access to the system can potentially discover and abuse the embedded key to decrypt sensitive information. This is a cryptographic weakness issue where a static, unchanging key is embedded in the codebase or binary rather than being dynamically generated or securely managed. The attack requires local system access but no authentication. Dell recommends upgrading to version 5.36.00.16 (Appliance) or 5.36.00.00 (Application) to remediate this issue.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00

References

Related threats