CVE-2026-78492
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 — in both its Appliance and Application forms — contains an improper certificate validation flaw (CWE-295), meaning it fails to adequately verify TLS certificates it accepts. An unauthenticated attacker with remote network access could potentially exploit this by presenting a certificate the gateway wrongly trusts; the high attack-complexity rating (AC:H) suggests exploitation likely requires a favorable network position such as an on-path location. Successful exploitation could lead to unauthorized access with high confidentiality and integrity impact, though no availability impact is indicated in the CVSS vector. Organizations running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Inventory environments for Dell SCG 5.0 deployments and upgrade the Appliance to 5.36.00.16 or later and the Application to 5.36.00.00 or later. Until patched, limit inbound network access to the gateway's interfaces, avoid exposing them to untrusted networks or the internet, and monitor Dell's security advisory for any additional hardening guidance.
| Dell Secure Connect Gateway 5.0 Appliance | All versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | All versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.