Sceawere
Vulnerability Detail
CVE-2026-80176UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Plaintext Password Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-257: Storing Passwords in a Recoverable Format
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-07T17:17:25.800Z",
"pubdate": "2026-09-07T17:17:25.800Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions contain a vulnerability characterized by the storage of passwords in plaintext.\nThis flaw resides within the local management architecture, posing a significant risk of information disclosure regarding sensitive authentication credentials.\nThe vulnerability is accessible to an attacker who has already obtained low-privileged local access to the underlying operating system or application environment.\nBy extracting these stored plaintext credentials, an unauthorized actor could potentially escalate privileges, compromise administrative accounts, or gain further lateral access within the infrastructure integrated with the SCG appliance.\nThe risk is mitigated by upgrading to versions 5.36.00.16 (Appliance) or 5.36.00.00 (Application) or later, which address the improper credential management practices.",
"technicalDetails": "The vulnerability stems from improper handling and storage of sensitive authentication data, specifically the use of plaintext formatting for password retention within the Dell SCG 5.0 ecosystem.\nThe root cause is a failure to implement robust cryptographic practices, such as irreversible hashing with salting or the utilization of secure key management services for protecting sensitive strings at rest within the appliance's local storage.\nExploitation requires that an attacker first establishes a local foothold on the SCG appliance. This could be achieved through various vectors, such as exploiting secondary vulnerabilities or leveraging existing local user sessions.\nOnce local access is secured, the attacker performs a file system or database query to locate configuration files or local data stores where passwords are cached. Because these credentials are not obfuscated or encrypted, the attacker can extract them directly without requiring specialized decryption tools or brute-force efforts.\nThe attack flow follows a predictable pattern: 1) The attacker gains low-privileged local system access; 2) The attacker identifies the specific directory or binary database storing the application's configuration parameters; 3) The attacker reads the configuration file or executes a command to parse the plaintext values; 4) The attacker retrieves the plaintext credentials to impersonate administrative users or access back-end systems managed by the gateway.\nThe scope of impact is limited to local exploitation; however, the post-exploitation impact is severe. Since the SCG is designed to handle connectivity for enterprise-grade hardware, the stolen credentials often provide high-level administrative access to both the appliance itself and potentially integrated components. Consequently, an attacker can maintain persistence, exfiltrate sensitive device telemetry, or manipulate the connectivity gateway to conduct further unauthorized actions within the environment.\nThis issue affects all iterations of Dell SCG 5.0 Appliance prior to 5.36.00.16 and Dell SCG 5.0 Application prior to 5.36.00.00. The vulnerability demonstrates a critical lapse in secure software development lifecycle (SDLC) practices regarding the storage of secrets."
}