Executive brief
Dell Secure Connect Gateway is a VPN/remote access appliance and application used to provide secure connectivity to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain hard-coded cryptographic keys that could allow an unauthenticated attacker to decrypt sensitive communications and gain unauthorized access to protected resources.
Technical details
This vulnerability involves the use of hard-coded cryptographic keys in Dell SCG 5.0, which is a cryptographic failure (CWE-321). An unauthenticated attacker with remote network access can potentially obtain these hard-coded keys from the application binaries or through reverse engineering, allowing them to decrypt sensitive data or forge authentication tokens. The vulnerability affects both the appliance (versions prior to 5.36.00.16) and application (versions prior to 5.36.00.00) deployments. No authentication or user interaction is required to exploit this flaw, making it a remote network-accessible vulnerability. Patched versions are available and should be deployed immediately to eliminate the exposure.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed