Sceawere

Vulnerability Detail

CVE-2026-80167UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Hard-Coded Cryptographic Key

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-321: Use of Hard-coded Cryptographic Key
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-07T17:17:25.683Z",
  "pubdate": "2026-09-07T17:17:25.683Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application editions contain a critical vulnerability classified as Use of Hard-coded Cryptographic Key.\nThis security flaw enables low-privileged local actors to bypass standard cryptographic protections, potentially leading to unauthorized information disclosure.\nThe vulnerability resides within the internal credential handling or encryption implementation of the appliance, where static keys are embedded directly into the software, making them retrievable by local users.\nThe risk is categorized as significant because successful exploitation facilitates the decryption of sensitive data, such as configuration files, logs, or cached credentials, which are intended to be protected by robust encryption.\nImpact includes the potential for full system compromise or lateral movement if the recovered keys are utilized to access further internal services or external systems connected via the SCG gateway.\nExploitation is limited to local access, requiring the attacker to possess a low-privileged account on the underlying operating system or within the application environment.\nThe issue affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.",
  "technicalDetails": "The root cause of this vulnerability is the implementation of hard-coded cryptographic keys within the SCG codebase. By embedding static cryptographic materials, the manufacturer has effectively negated the security benefits of encryption, as these keys are discoverable via binary analysis, reverse engineering of configuration files, or local inspection of the file system.\nIn a secure implementation, cryptographic keys should be generated dynamically or derived from environment-specific factors (e.g., hardware-backed keystores or Trusted Platform Module integration). In this instance, the static nature of the key allows any actor with local shell access or sufficient read permissions to extract the key material.\nThe attack flow begins with the attacker gaining local access to the Dell SCG appliance. Once access is established, the attacker navigates to the application directories where sensitive cryptographic modules or configuration files are stored. By analyzing the binaries or decrypted configuration blocks, the attacker identifies the static key used for symmetric or asymmetric encryption routines.\nOnce the key is obtained, the attacker can decrypt sensitive data residing on the appliance or intercept and decrypt incoming/outgoing traffic if the key is associated with session handling or data-at-rest encryption. This process bypasses the intended confidentiality controls, leading to the exposure of credentials, system logs, or customer-specific telemetry data managed by the SCG gateway.\nAffected products include Dell SCG 5.0 Appliance (versions < 5.36.00.16) and Dell SCG 5.0 Application (versions < 5.36.00.00).\nPost-exploitation, the impact is primarily information disclosure. However, because these keys are often reused across multiple installations of the same product version, the compromise of one instance can lead to the widespread compromise of all vulnerable deployments within an enterprise environment. Furthermore, if the recovered key is used to sign or encrypt administrative commands, the attacker might gain the ability to inject malicious configurations or escalate their local privileges to root/administrator status."
}
CVE-2026-80167: Dell SCG Hard-Coded Cryptographic Key (MEDIUM Severity, CVSS: 5.5) - Sceawere