ZeroHour

CVE-2026-79636

large

Certificate Host Mismatch Validation Flaw in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.0 high
EPSS
<1%p3
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 fails to properly validate that the certificate presented by a remote endpoint matches the expected host (CWE-297, Improper Validation of Certificate with Host Mismatch). An unauthenticated remote attacker who can intercept or spoof the hosts the gateway communicates with — typically requiring a man-in-the-middle or network-spoofing position, consistent with the high attack complexity in the CVSS vector — could exploit this to gain unauthorized access, with potential for high confidentiality impact plus low integrity and availability impact. Affected deployments are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. As of this analysis there is no evidence of exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later, and verify the running version in the gateway's management interface. As an interim mitigation, restrict network access to and from the gateway and ensure the network path to its remote endpoints cannot be intercepted by untrusted parties. Monitor Dell's security advisory for updates, since no public exploit or in-the-wild exploitation is currently known.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largelikely on the order of tens of thousands of enterprise site deployments (exact install base not publicly disclosed) — Estimated from deployment patterns: Secure Connect Gateway is typically deployed one-per-site or per-datacenter at enterprises using Dell SupportAssist/Secure Connect remote support across Dell's large enterprise install base, and no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-297
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.