Junglewise Threat Intelligence

CVE-2026-80176: Dell Secure Connect Gateway plaintext password storage

CVE-2026-80176 · Severity: medium · CVSS 4.7 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) 5.0 stores sensitive passwords in plaintext, allowing any local attacker with system access to retrieve administrative credentials and gain unauthorized control. This directly exposes customer authentication data and enables attackers to impersonate administrators, access protected systems, and potentially establish persistent access to corporate networks.

Technical details

CVE-2026-80176 is a plaintext storage of password vulnerability in Dell SCG 5.0 Appliance (versions prior to 5.36.00.16) and Application (versions prior to 5.36.00.00). The vulnerability requires local access and low privilege level to exploit. An attacker with local system access can read plaintext-stored passwords from the affected component's storage mechanism, enabling information disclosure and potential privilege escalation or lateral movement within the infrastructure. The vulnerability is patched in SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed

References

Related threats