Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and VPN connectivity. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain hard-coded credentials that allow unauthenticated attackers with network access to bypass authentication and gain unauthorized access to the system, potentially compromising protected network resources.
Technical details
This vulnerability is a use of hard-coded credentials flaw in Dell SCG 5.0 affecting both the appliance (versions before 5.36.00.16) and application (versions before 5.36.00.00). An unauthenticated attacker with remote network access can exploit this by using the embedded credentials to authenticate to the gateway without requiring valid user credentials. The vulnerability allows attackers to bypass the authentication protection mechanism that is designed to restrict access to the SCG system. Patched versions are available; users should upgrade to version 5.36.00.16 (appliance) or 5.36.00.00 (application) or later.
Affected products
- Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
- Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: Published via NVD and Dell advisory DSA-2026-382