Insufficient Entropy Vulnerability in Dell SCG 5.0 Appliance and Application
CVE-2026-80171

4.7MEDIUM

What is CVE-2026-80171?

The Dell Secure Connect Gateway 5.0 Appliance and Application have a potential vulnerability due to insufficient entropy in their pseudo-random number generator (PRNG). This flaw allows low privileged attackers with local access to manipulate the entropy sources, resulting in possible elevation of privileges. Users are advised to update to the latest versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Secure Connect Gateway 5.0 - Appliance 0 < 5.36.00.16 or later

Secure Connect Gateway 5.0 - Application 0 < 5.36.00.00 or later

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.