Junglewise Threat Intelligence

CVE-2026-80171: Dell Secure Connect Gateway insufficient entropy in PRNG

CVE-2026-80171 · Severity: medium · CVSS 4.7 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a virtual appliance and application used to provide secure remote access and gateway functionality for enterprise networks. A flaw in the random number generator used for cryptographic operations could allow a local attacker to predict security tokens and gain unauthorized administrative access to the system.

Technical details

CVE-2026-80171 is an insufficient entropy vulnerability in the pseudo-random number generator (PRNG) used by Dell SCG 5.0 prior to version 5.36.00.16 (appliance) or 5.36.00.00 (application). The vulnerability allows a low-privileged local attacker to exploit predictable randomness in cryptographic operations, potentially leading to privilege escalation. The root cause lies in inadequate entropy seeding or use of a weak PRNG algorithm in security-sensitive contexts. No authentication is required; only local access is needed. A patch is available in versions 5.36.00.16 and later.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats