Sceawere
Vulnerability Detail
CVE-2026-80170UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Hard-Coded Credentials
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-798: Use of Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-07T14:16:55.173Z",
"pubdate": "2026-09-07T14:16:55.173Z",
"executiveSummary": "This vulnerability involves the presence of hard-coded credentials within Dell SCG 5.0 Appliance and Application deployments. Classified as a Use of Hard-coded Credentials (CWE-798), the flaw exposes the system to unauthorized access and security control subversion. The vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated, remote attacker can leverage these embedded credentials to bypass standard authentication mechanisms, effectively gaining unauthorized access to the appliance. The risk implication is critical, as it allows attackers to compromise the integrity and confidentiality of the management interface without needing valid user accounts or interactive login attempts. This bypass effectively negates the security perimeter established by the appliance's authentication modules.",
"technicalDetails": "The vulnerability resides in the core authentication mechanism of the Dell SCG 5.0 suite, where static, hard-coded credentials exist within the codebase or configuration artifacts. Hard-coded credentials are cryptographic or administrative secrets embedded directly into the application's binary, script files, or configuration schemas rather than being managed through secure, dynamic storage mechanisms.\nFrom an exploitation perspective, the attack flow initiates with a remote, unauthenticated actor identifying the specific endpoint or service interface protected by these embedded credentials. Because these credentials are static and ubiquitous across all vulnerable instances, an attacker does not need to perform brute-force or dictionary attacks. Once the target service is identified, the attacker supplies the hard-coded credentials to the authentication module. The system, failing to distinguish between legitimate administrative traffic and unauthorized requests, validates the credentials against the hard-coded values and issues an authenticated session token to the attacker.\nThe root cause is the improper implementation of credential management, specifically the failure to rotate or externalize administrative secrets during the build process. This vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Since the vulnerability is located at the authentication layer, it bypasses the primary protection mechanism intended to gate access to the appliance's management capabilities. The network exposure is broad, as any reachable management interface or service port containing these credentials is susceptible to exploitation via standard network protocols.\nPost-exploitation, the impact is severe. An attacker operating with these credentials effectively assumes the privileges of a legitimate user. Depending on the scope of the hard-coded account, this may allow for total system control, including the ability to modify system configurations, extract sensitive data, intercept telemetry or management traffic, and establish persistence within the appliance environment. The lack of audit logs specifically tied to legitimate user accounts complicates forensic analysis, as the usage of a hard-coded account may be indistinguishable from legitimate maintenance activity unless behavioral analytics are deployed to identify anomalous administrative commands issued from unauthorized network segments."
}