ZeroHour

CVE-2026-79637

Improper Certificate Validation in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains an improper certificate validation flaw (CWE-295) in which the gateway fails to correctly validate TLS certificates. Because the flaw is network-exploitable by an unauthenticated attacker but carries high attack complexity, exploitation most likely requires an attacker in a network position, such as a man-in-the-middle or a rogue endpoint presenting a fraudulent certificate. A successful attack could lead to unauthorized access to the gateway or its communication channel, with high impact on confidentiality and integrity and low impact on availability per the CVSS scoring. Users are affected if they run the SCG 5.0 Appliance at versions prior to 5.36.00.16 or the SCG 5.0 Application at versions prior to 5.36.00.00. No public proof-of-concept, CISA KEV listing, or reports of in-the-wild exploitation are known at this time.

What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later. Until patched, minimize the gateway's network exposure, restrict which network segments can reach it, and monitor Dell's security advisories for updates.

Affected
Dell Secure Connect Gateway 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.