Junglewise Threat Intelligence

CVE-2026-79735: Dell Secure Connect Gateway hard-coded cryptographic key

CVE-2026-79735 · Severity: medium · CVSS 4.4 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a VPN/remote access appliance and application used to provide secure connectivity to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain hard-coded cryptographic keys that could allow an unauthenticated attacker to decrypt sensitive communications and gain unauthorized access to protected resources.

Technical details

This vulnerability involves the use of hard-coded cryptographic keys in Dell SCG 5.0, which is a cryptographic failure (CWE-321). An unauthenticated attacker with remote network access can potentially obtain these hard-coded keys from the application binaries or through reverse engineering, allowing them to decrypt sensitive data or forge authentication tokens. The vulnerability affects both the appliance (versions prior to 5.36.00.16) and application (versions prior to 5.36.00.00) deployments. No authentication or user interaction is required to exploit this flaw, making it a remote network-accessible vulnerability. Patched versions are available and should be deployed immediately to eliminate the exposure.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats