Sceawere

Vulnerability Detail

CVE-2026-79738UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Hard-Coded Credentials

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
20h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-798: Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-09T14:17:17.917Z",
  "pubdate": "2026-09-09T14:17:17.917Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00 are susceptible to a critical vulnerability categorized as a Use of Hard-coded Credentials.\nThis vulnerability stems from the inclusion of static, embedded authentication tokens or credentials within the application or appliance image, which can be leveraged by unauthorized parties.\nThe vulnerability poses a severe risk as it allows an unauthenticated, remote attacker to bypass standard authentication mechanisms to gain unauthorized access to sensitive system resources.\nSuccessful exploitation facilitates information exposure, potentially leading to the compromise of system configurations, diagnostic data, or proprietary information managed by the gateway.\nGiven that the vulnerability is exploitable remotely without requiring prior authentication, it represents a significant security oversight. The primary risk implication is a total breach of the confidentiality of the affected SCG instance.\nAffected organizations should prioritize updating to the remediated versions specified by Dell to neutralize the hard-coded credential threat.",
  "technicalDetails": "The vulnerability resides within the authentication framework of Dell Secure Connect Gateway (SCG) 5.0, where developers inadvertently included hard-coded credentials within the application logic or appliance firmware.\nA hard-coded credential vulnerability occurs when software uses an embedded password or secret to facilitate system access, authentication, or cryptographic operations. In this context, the credentials are likely embedded within the source code, configuration files, or compiled binaries of the SCG platform.\nThe attack flow initiates when an unauthenticated, remote attacker identifies the specific service or interface utilizing these hard-coded credentials. Because these credentials are immutable without a software patch, they remain constant across all vulnerable deployments, enabling an attacker to craft a payload that systematically authenticates to the target system.\nExploitation does not require the attacker to possess prior knowledge of unique user credentials or secondary authentication tokens. By utilizing the static credentials, the attacker successfully bypasses the authentication gate of the SCG, gaining entry to the administrative or operational interface as if they were a legitimate user.\nOnce authenticated, the attacker's capabilities are determined by the privilege level associated with the hard-coded account. Typically, such accounts often possess elevated or service-level privileges, allowing the attacker to interact with the underlying operating system, query the application's database, or intercept Secure Remote Services traffic.\nThe post-exploitation impact includes unauthorized information exposure, where sensitive diagnostic logs, system configuration details, or connection metadata stored within the SCG appliance become accessible to the adversary. Furthermore, an attacker might leverage this unauthorized access to pivot deeper into the network infrastructure that the SCG is designed to monitor and manage, thereby expanding the scope of the incident.\nAffected software versions include Dell SCG 5.0 Appliance versions strictly earlier than 5.36.00.16 and Dell SCG 5.0 Application versions strictly earlier than 5.36.00.00. The vulnerability persists until the manufacturer replaces the hard-coded secrets with a dynamic, secure, or externalized authentication mechanism, which is delivered via the specified version updates."
}
CVE-2026-79738: Dell SCG Hard-Coded Credentials (HIGH Severity, CVSS: 7.5) | Sceawere