CVE-2026-79637
—Improper Certificate Validation in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains an improper certificate validation flaw (CWE-295) in which the gateway fails to correctly validate TLS certificates. Because the flaw is network-exploitable by an unauthenticated attacker but carries high attack complexity, exploitation most likely requires an attacker in a network position, such as a man-in-the-middle or a rogue endpoint presenting a fraudulent certificate. A successful attack could lead to unauthorized access to the gateway or its communication channel, with high impact on confidentiality and integrity and low impact on availability per the CVSS scoring. Users are affected if they run the SCG 5.0 Appliance at versions prior to 5.36.00.16 or the SCG 5.0 Application at versions prior to 5.36.00.00. No public proof-of-concept, CISA KEV listing, or reports of in-the-wild exploitation are known at this time.
What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later. Until patched, minimize the gateway's network exposure, restrict which network segments can reach it, and monitor Dell's security advisories for updates.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.