Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance and application used to provide secure connectivity to corporate networks. This vulnerability allows an unauthenticated attacker with network access to log in using hard-coded credentials, potentially gaining administrative access to the gateway and exposing sensitive network traffic and configuration data.
Technical details
The vulnerability is a use of hard-coded credentials in Dell SCG 5.0 Appliance (versions prior to 5.36.00.16) and Dell SCG 5.0 Application (versions prior to 5.36.00.00). An unauthenticated attacker with remote network access can exploit this by authenticating with embedded credentials, bypassing normal access controls. No user interaction or local access is required. An attacker can achieve unauthorized access to the system, potentially leading to information exposure, configuration tampering, and lateral movement into protected networks. Patch versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) or later address this issue.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: Published in NVD and DSA-2026-382
- 2026-09-09: advisory: Dell Security Advisory DSA-2026-382