PatchSiren cyber security CVE debrief
CVE-2026-78487 Dell CVE debrief
A low-privileged attacker with local access could potentially exploit the Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, leading to information disclosure. This vulnerability requires medium-priority defensive actions to prevent potential information disclosure. System administrators and security teams should assess exposure, prioritize remediation, and implement compensating controls to monitor and detect potential exploitation attempts.
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
System administrators and security teams responsible for Dell SCG 5.0 Appliance and Dell SCG 5.0 Application should assess exposure and prioritize remediation. They should also implement compensating controls to monitor and detect potential exploitation attempts.
Why it matters
The Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance and Dell SCG 5.0 Application requires medium-priority defensive actions to prevent potential information disclosure. System administrators and security teams should assess exposure, prioritize remediation, and implement compensating controls to monitor and detect potential exploitation attempts.
- Information disclosure may occur due to exploitation of the vulnerability
- Low-privileged attackers with local access may be able to exploit the vulnerability
- Remediation priority is medium due to the CVSS score of 5.5
Technical summary
The Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 contain a Use of Hard-coded Cryptographic Key vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The vulnerability requires medium-priority defensive actions to prevent potential information disclosure. System administrators and security teams should assess exposure, prioritize remediation, and implement compensating controls to monitor and detect potential exploitation attempts.
Defensive priority
Medium-priority defensive actions are recommended to address the Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance and Dell SCG 5.0 Application.
Recommended defensive actions
- Review and apply the security update for Dell Secure Connect Gateway Virtual Edition
- Verify the version of Dell SCG 5.0 Appliance and Dell SCG 5.0 Application
- Implement compensating controls to monitor and detect potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected products. The vulnerability is a Use of Hard-coded Cryptographic Key vulnerability in Dell SCG 5.0 Appliance and Dell SCG 5.0 Application. The CVE record was published on 2026-09-07T14:16:54.340Z and has not been modified since then. The NVD vulnerability detail page provides additional information on the vulnerability, including its CVSS score and affected products.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78487 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78487
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78487 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78487
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.