CVE-2026-79636
largeCertificate Host Mismatch Validation Flaw in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 fails to properly validate that the certificate presented by a remote endpoint matches the expected host (CWE-297, Improper Validation of Certificate with Host Mismatch). An unauthenticated remote attacker who can intercept or spoof the hosts the gateway communicates with — typically requiring a man-in-the-middle or network-spoofing position, consistent with the high attack complexity in the CVSS vector — could exploit this to gain unauthorized access, with potential for high confidentiality impact plus low integrity and availability impact. Affected deployments are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. As of this analysis there is no evidence of exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later, and verify the running version in the gateway's management interface. As an interim mitigation, restrict network access to and from the gateway and ensure the network path to its remote endpoints cannot be intercepted by untrusted parties. Monitor Dell's security advisory for updates, since no public exploit or in-the-wild exploitation is currently known.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-297
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.