Executive brief
Dell Secure Connect Gateway (SCG) is a virtual appliance and application used to provide secure remote access and gateway functionality for enterprise networks. A flaw in the random number generator used for cryptographic operations could allow a local attacker to predict security tokens and gain unauthorized administrative access to the system.
Technical details
CVE-2026-80171 is an insufficient entropy vulnerability in the pseudo-random number generator (PRNG) used by Dell SCG 5.0 prior to version 5.36.00.16 (appliance) or 5.36.00.00 (application). The vulnerability allows a low-privileged local attacker to exploit predictable randomness in cryptographic operations, potentially leading to privilege escalation. The root cause lies in inadequate entropy seeding or use of a weak PRNG algorithm in security-sensitive contexts. No authentication is required; only local access is needed. A patch is available in versions 5.36.00.16 and later.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed