CVE-2026-80176
Received Received - Intake

Plaintext Password Storage in Dell SCG Appliance and Application

Vulnerability report for CVE-2026-80176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: Dell

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dell scg to 5.36.00.16 (exc)
dell scg to 5.36.00.00 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-257 The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dell SCG versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) store passwords in plaintext. A low-privileged attacker with local access could exploit this to read sensitive credentials, leading to potential information disclosure.

Impact Analysis

If exploited, this vulnerability could allow an attacker to access stored passwords, potentially leading to unauthorized access to systems or data. This may result in data breaches, loss of sensitive information, or further compromise of the affected Dell SCG environment.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR and HIPAA by exposing sensitive personal or health data due to plaintext password storage. Organizations may face penalties for failing to protect such data adequately.

Mitigation Strategies

Update Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later to address the plaintext password storage issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80176. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart