CVE-2026-80134

7.7

Dell · Secure Connect Gateway

Dell Secure Connect Gateway contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to gain unauthorized access to the affected system.

Executive summary

A critical vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to bypass security controls and gain unauthorized access due to the use of hard-coded credentials.

Vulnerability

The software utilizes hard-coded credentials, which enables an unauthenticated attacker with network access to bypass authentication mechanisms and compromise the system. This CWE-798 flaw represents a fundamental security failure in credential management.

Business impact

The presence of hard-coded credentials poses a severe risk to organizational security, as it provides a direct path for unauthorized actors to access management interfaces. With a CVSS score of 7.7, this high-severity flaw could lead to full system compromise, data exfiltration, or the manipulation of gateway configurations, resulting in significant operational disruption.

Remediation

Immediate Action: Upgrade the Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later, or the Application to version 5.36.00.00 or later, as specified in the vendor security advisory.

Proactive Monitoring: Audit system access logs for unusual login activity or unauthorized attempts to access administrative endpoints from external network segments.

Compensating Controls: Restrict network access to the Secure Connect Gateway interface using firewall rules or VPNs to ensure that only authorized management subnets can reach the service.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this vulnerability and the ease of exploitation associated with hard-coded credentials, immediate patching is required to secure the environment. Organizations should prioritize updating their Dell Secure Connect Gateway instances to the versions identified above to eliminate the risk of unauthorized access.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources