Junglewise Threat Intelligence

CVE-2026-80170: Dell Secure Connect Gateway hard-coded credentials vulnerability

CVE-2026-80170 · Severity: medium · CVSS 6.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and VPN connectivity. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain hard-coded credentials that allow unauthenticated attackers with network access to bypass authentication and gain unauthorized access to the system, potentially compromising protected network resources.

Technical details

This vulnerability is a use of hard-coded credentials flaw in Dell SCG 5.0 affecting both the appliance (versions before 5.36.00.16) and application (versions before 5.36.00.00). An unauthenticated attacker with remote network access can exploit this by using the embedded credentials to authenticate to the gateway without requiring valid user credentials. The vulnerability allows attackers to bypass the authentication protection mechanism that is designed to restrict access to the SCG system. Patched versions are available; users should upgrade to version 5.36.00.16 (appliance) or 5.36.00.00 (application) or later.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Published via NVD and Dell advisory DSA-2026-382

References

Related threats