Junglewise Threat Intelligence

CVE-2026-80167: Dell Secure Connect Gateway hard-coded cryptographic key vulnerability

CVE-2026-80167 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a network security appliance used to manage remote access and VPN connectivity for enterprise networks. Versions before 5.36.00.16 (appliance) and 5.36.00.00 (application) contain a hard-coded cryptographic key that an attacker with local access could exploit to decrypt sensitive data or forge authentication tokens, compromising the security of remote connections and potentially exposing customer data.

Technical details

The vulnerability is a use of hard-coded cryptographic keys in Dell Secure Connect Gateway versions 5.0 prior to patch 5.36.00.16 (appliance) and 5.36.00.00 (application). An attacker with local access to the system can extract the hard-coded key and use it to decrypt encrypted communications or forge cryptographic signatures. This is a CWE-321 class vulnerability requiring local access; the impact includes information disclosure and potential authentication bypass. Patches are available and Dell recommends immediate upgrade.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Security advisory published by Dell

References

Related threats