Sceawere

Vulnerability Detail

CVE-2026-80057UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hard-Coded Cryptographic Key Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-321: Use of Hard-coded Cryptographic Key
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-07T15:17:32.397Z",
  "pubdate": "2026-09-07T15:17:32.397Z",
  "executiveSummary": "This vulnerability involves the presence of a hard-coded cryptographic key within Dell SCG 5.0 Appliance and Application versions. Classified as an issue involving the use of hard-coded credentials, this flaw permits unauthorized access to sensitive cryptographic material. The vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Exploitation of this vulnerability could result in unauthorized information disclosure, compromising the confidentiality of encrypted data or communication channels processed by the appliance. Successful exploitation requires an attacker to possess low-privileged local access to the target system. Given the nature of hard-coded secrets, the risk is significant as the cryptographic protections provided by the affected key are effectively bypassed, allowing an attacker to decrypt traffic or sensitive local data without requiring prior knowledge of specific administrative credentials or authentication tokens. Organizations should prioritize updating to the specified secure versions to remediate the vulnerability.",
  "technicalDetails": "The vulnerability resides in the core implementation of the Dell SCG 5.0 Appliance and Application software, specifically concerning the management of cryptographic primitives. The root cause is the improper storage of a cryptographic key directly within the software source code or configuration files, rather than utilizing a secure, dynamic key management system or hardware security module (HSM). Because the key is hard-coded, it remains static across all deployments of the affected versions.\nFrom an exploitation perspective, a local attacker with low-level privileges can navigate the file system to locate the binary or configuration files containing the embedded key. Upon identification, the attacker can extract the key and utilize it to perform unauthorized cryptographic operations. This attack flow involves the attacker gaining local command-line access or shell execution rights, which provides the necessary visibility into the application directory structure. Once the key is extracted, the attacker can use it to intercept or decrypt data handled by the SCG software that relies on this specific cryptographic mechanism.\nThe scope of impact is broad due to the static nature of the hard-coded secret; it does not change based on individual system installations. Consequently, the cryptographic security of the affected Dell SCG versions is entirely undermined. The vulnerability facilitates information disclosure by bypassing the intended encryption boundaries. This can lead to the exposure of sensitive logs, configuration backups, or intercepted network communications, depending on the role the specific key plays within the application architecture. The exploitation does not require advanced network-level access or elevated administrative privileges, but relies on the existence of the static key in the application's executable or supporting configuration assets. The absence of dynamic key derivation or secure key storage practices represents a failure in following established secure coding standards for cryptographic modules."
}
CVE-2026-80057: Hard-Coded Cryptographic Key Vulnerability (MEDIUM Severity, CVSS: 5.5) - Sceawere