Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance used to provide secure remote access and connectivity. Versions prior to 5.36.00.16 contain hard-coded credentials that an unauthenticated remote attacker could exploit to gain unauthorized access to the system, potentially compromising confidential data or enabling further attacks on the network.
Technical details
The vulnerability exists in Dell SCG 5.0 Appliance (before 5.36.00.16) and SCG 5.0 Application (before 5.36.00.00) due to the use of hard-coded credentials in the system. An unauthenticated attacker with network access can exploit this weakness to authenticate to the system without valid credentials. This allows unauthorized access and information exposure. The vulnerability requires no authentication, user interaction, or special network conditions to exploit, making it easily accessible to remote attackers on the network.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed