CVE-2026-78491
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application contain an improper certificate validation flaw (CWE-295), meaning the gateway does not adequately validate TLS certificates when handling remote connections. An unauthenticated attacker with remote access could exploit this, for example by presenting a spoofed or rogue certificate, to gain unauthorized access; the CVSS 3.1 vector scores the impact as low on integrity and high on availability, with no direct confidentiality impact. Affected deployments are SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00, which are separately versioned products. There are no known reports of exploitation in the wild, no public proof-of-concept, and the issue is not in the CISA KEV catalog.
What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later, following Dell's security advisory. Until patched, restrict the gateway's management interfaces to trusted networks only and review logs for unexpected remote connections. Inventory both the appliance and application variants separately, since they follow different version tracks.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.