CVE-2026-78494
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
CVE-2026-78494 is an improper certificate validation flaw (CWE-295) in Dell Secure Connect Gateway 5.0, where the gateway does not adequately validate TLS certificates presented during its network communications. An unauthenticated attacker with remote access could trigger it, and the CVSS vector's high attack complexity (AC:H) suggests exploitation likely requires a favorable network position, such as an on-path (man-in-the-middle) vantage point on the gateway's connections. Successful exploitation could lead to unauthorized access with high impact on confidentiality and integrity (CVSS 3.1 score of 7.4, High), with no availability impact. All deployments running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later, and verify the currently installed version in the Secure Connect Gateway interface. Until patched, restrict access to the gateway's network and management interfaces and limit or segment the network path it uses to reach Dell back-end connectivity endpoints to reduce man-in-the-middle exposure. With no known exploits or public PoC, standard patch cadence is reasonable, but gateways exposed to broader internal networks should be prioritized.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 (fixed in 5.36.00.16) |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 (fixed in 5.36.00.00) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.