CVE-2026-79639
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
CVE-2026-79639 is an improper certificate validation flaw (CWE-295) in Dell Secure Connect Gateway (SCG) 5.0, affecting the Appliance edition prior to 5.36.00.16 and the Application edition prior to 5.36.00.00. Because the gateway does not correctly validate X.509/TLS certificates, an unauthenticated attacker with network access — adjacent per the CVSS 3.1 vector (AV:A), which the advisory describes as remote access — could impersonate a trusted endpoint or present an invalid certificate and connect to the gateway without valid credentials. A successful exploit leads to unauthorized access, scored high for confidentiality and low for integrity and availability, for an overall CVSS 3.1 score of 7.6 (high). Affected organizations are those running SCG 5.0, the appliance or virtual application used to provide secure remote-support connectivity between Dell EMC infrastructure and Dell support services. No public proof of concept, no listing in the CISA KEV catalog, and EPSS currently assigns a 0.1% (1st percentile) probability of exploitation in the next 30 days, so no in-the-wild exploitation is known.
What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later, and verify currently deployed versions in the gateway management interface. Until patched, limit access to the gateway to trusted management/production network segments, since the attack requires adjacent network access. Given low EPSS (0.1%) and no known exploitation, normal-cycle patching is defensible, but prioritize gateways that are broadly reachable within your network.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.