Sceawere

Vulnerability Detail

CVE-2026-80134UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Hard-coded Credentials Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
1h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-798: Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-09-07T13:20:38.923Z",
  "pubdate": "2026-09-07T13:20:38.923Z",
  "executiveSummary": "This vulnerability involves the presence of hard-coded credentials within Dell SCG 5.0 Appliance and Application editions, specifically affecting versions prior to 5.36.00.16 and 5.36.00.00, respectively.\nCategorized as a 'Use of Hard-coded Credentials' flaw, this security oversight introduces a critical risk of unauthorized access to the affected systems.\nThe vulnerability is accessible to unauthenticated, remote attackers who possess network connectivity to the target appliance.\nSuccessful exploitation bypasses standard authentication mechanisms, granting the adversary potentially elevated access to the system without requiring valid user credentials.\nGiven the nature of secure management gateways, the compromise of an SCG appliance can lead to broader security infrastructure degradation, loss of data confidentiality, and potential unauthorized control over managed devices.\nImmediate remediation via vendor-supplied updates is required to neutralize the exposure and prevent exploitation by threat actors scanning for default or hard-coded backdoor account access.",
  "technicalDetails": "The vulnerability resides within the authentication logic or configuration management modules of the Dell SCG 5.0 software ecosystem. The root cause is the implementation of static, non-changeable credentials embedded directly into the application code or the underlying appliance image during the build process.\nHard-coded credentials violate fundamental secure coding principles by bypassing the intended Identity and Access Management (IAM) framework. Because these credentials are immutable through standard administrative interfaces, they provide a persistent, predictable entry point for any actor aware of the secret strings.\nThe attack flow commences with the adversary identifying an exposed Dell SCG instance via network reconnaissance, such as identifying specific services or listening ports common to the appliance via scanning tools like Nmap or Shodan. Once a target is identified, the attacker attempts to authenticate using the known hard-coded credentials. Because the system is designed to accept these credentials as valid administrative tokens, the authentication handshake succeeds without the need for a secondary challenge or valid user session.\nThe technical impact of this vulnerability is severe because it circumvents the entire authorization layer. Once authenticated, the attacker may gain access to management functions, potentially allowing for system reconfiguration, configuration file extraction, or the monitoring of managed environment traffic. Depending on the level of privilege associated with the hard-coded account, an attacker could potentially execute arbitrary administrative commands, manipulate alerts, or pivot deeper into the internal network environment where the SCG appliance is situated.\nThe exposure is exacerbated by the lack of requirement for authentication prior to the exploit attempt. The attacker does not need to leverage social engineering or brute-force tactics, as the credentials are static and universal across the affected versions. Exploitation is limited only by the attacker's ability to reach the appliance over the network interface. Consequently, any SCG deployment reachable from an untrusted network segment, including public-facing interfaces, is at high risk of immediate compromise. Post-exploitation, an attacker could maintain persistent access by creating new, legitimate-looking administrative accounts, effectively masking their presence and ensuring continued access even if the original vulnerable service is partially remediated."
}
CVE-2026-80134: Dell SCG Hard-coded Credentials Vulnerability (HIGH Severity, CVSS: 7.7) - Sceawere