ZeroHour

CVE-2026-79644

large

Improper Certificate Validation in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.4 high
EPSS
<1%p4
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 — in both its Appliance and Application forms — fails to properly validate TLS certificates (CWE-295), meaning connections may be accepted without correctly verifying the identity of the remote endpoint. An unauthenticated attacker with remote network access could exploit the flaw; the high attack-complexity score (AC:H) in the CVSS vector indicates exploitation depends on favorable conditions, such as the attacker being positioned to intercept or influence the connection. A successful exploit leads to unauthorized access with high impact to confidentiality and integrity, while availability is unaffected. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16, or SCG 5.0 Application versions prior to 5.36.00.00, are affected. There is no sign of active exploitation: no public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.1% probability of exploitation within 30 days.

What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. In the interim, restrict network access to the gateway and limit exposure of its remote-support connections. Given the absence of known exploitation and the low EPSS score, this can be handled as routine patching, but inventory your environment to confirm which gateway form and version you run.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largeon the order of tens of thousands of gateway deployments worldwide (estimated; no public install counts available) — Secure Connect Gateway is deployed as a per-environment remote-support gateway (appliance or application) across Dell's large enterprise customer base, and typical patterns of one or a few gateways per organization imply an order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.