PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78487 Dell CVE debrief

A low-privileged attacker with local access could potentially exploit the Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, leading to information disclosure. This vulnerability requires medium-priority defensive actions to prevent potential information disclosure. System administrators and security teams should assess exposure, prioritize remediation, and implement compensating controls to monitor and detect potential exploitation attempts.

Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

System administrators and security teams responsible for Dell SCG 5.0 Appliance and Dell SCG 5.0 Application should assess exposure and prioritize remediation. They should also implement compensating controls to monitor and detect potential exploitation attempts.

Why it matters

The Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance and Dell SCG 5.0 Application requires medium-priority defensive actions to prevent potential information disclosure. System administrators and security teams should assess exposure, prioritize remediation, and implement compensating controls to monitor and detect potential exploitation attempts.

  • Information disclosure may occur due to exploitation of the vulnerability
  • Low-privileged attackers with local access may be able to exploit the vulnerability
  • Remediation priority is medium due to the CVSS score of 5.5

Technical summary

The Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 contain a Use of Hard-coded Cryptographic Key vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The vulnerability requires medium-priority defensive actions to prevent potential information disclosure. System administrators and security teams should assess exposure, prioritize remediation, and implement compensating controls to monitor and detect potential exploitation attempts.

Defensive priority

Medium-priority defensive actions are recommended to address the Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance and Dell SCG 5.0 Application.

Recommended defensive actions

  • Review and apply the security update for Dell Secure Connect Gateway Virtual Edition
  • Verify the version of Dell SCG 5.0 Appliance and Dell SCG 5.0 Application
  • Implement compensating controls to monitor and detect potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected products. The vulnerability is a Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance and Dell SCG 5.0 Application. The CVE record was published on 2026-09-07T14:16:54.340Z and has not been modified since then. The NVD vulnerability detail page provides additional information on the vulnerability, including its CVSS score and affected products.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78487 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78487

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78487 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78487

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.