ZeroHour

CVE-2026-78492

large

Improper Certificate Validation in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 — in both its Appliance and Application forms — contains an improper certificate validation flaw (CWE-295), meaning it fails to adequately verify TLS certificates it accepts. An unauthenticated attacker with remote network access could potentially exploit this by presenting a certificate the gateway wrongly trusts; the high attack-complexity rating (AC:H) suggests exploitation likely requires a favorable network position such as an on-path location. Successful exploitation could lead to unauthorized access with high confidentiality and integrity impact, though no availability impact is indicated in the CVSS vector. Organizations running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Inventory environments for Dell SCG 5.0 deployments and upgrade the Appliance to 5.36.00.16 or later and the Application to 5.36.00.00 or later. Until patched, limit inbound network access to the gateway's interfaces, avoid exposing them to untrusted networks or the internet, and monitor Dell's security advisory for any additional hardening guidance.

Affected
Dell Secure Connect Gateway 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
largeplausibly on the order of tens of thousands of deployed gateway/application instances (estimate; no public install counts or scan data) — Dell SCG is deployed roughly once per enterprise environment to broker SupportAssist connectivity for Dell hardware fleets, and the affected range spans all 5.x releases before the 5.36 fixes, so given Dell's large enterprise support…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.