Executive brief
Dell Secure Connect Gateway is a network appliance and application used to provide secure remote access and connectivity. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain a hard-coded cryptographic key that could allow a local attacker to decrypt sensitive data and compromise system security.
Technical details
This vulnerability involves the use of hard-coded cryptographic keys in the Dell SCG application. The vulnerability can be exploited by a low-privileged attacker with local access to the affected system. By leveraging the embedded cryptographic key, an attacker can decrypt sensitive information stored or transmitted by the application, leading to information disclosure. The vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. A patch is available in the form of version 5.36.00.16 (appliance) and 5.36.00.00 (application).
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: CVE-2026-80057 published