CVE-2026-80176
published 2026-09-07CVE-2026-80176: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password…
PriorityP421medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.08%
0.2th percentile
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | secure_connect_gateway_5.0_appliance | < 5.36.00.16 or later | 5.36.00.16 or later |
| dell | secure_connect_gateway_5.0_application | < 5.36.00.00 or later | 5.36.00.00 or later |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability.
ghsa_unreviewed·2026-09-07
CVE-2026-80176 [MEDIUM] CWE-257 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
VulDB
Dell Secure Connect Gateway missing encryption
vuldb·2026-09-07·CVSS 4.7
CVE-2026-80176 [MEDIUM] Dell Secure Connect Gateway missing encryption
A vulnerability classified as problematic has been found in Dell Secure Connect Gateway. Affected is an unknown function. The manipulation leads to missing encryption of sensitive data.
This vulnerability is traded as CVE-2026-80176. An attack has to be approached locally. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-07
Published