CVE-2026-79644
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 — in both its Appliance and Application forms — fails to properly validate TLS certificates (CWE-295), meaning connections may be accepted without correctly verifying the identity of the remote endpoint. An unauthenticated attacker with remote network access could exploit the flaw; the high attack-complexity score (AC:H) in the CVSS vector indicates exploitation depends on favorable conditions, such as the attacker being positioned to intercept or influence the connection. A successful exploit leads to unauthorized access with high impact to confidentiality and integrity, while availability is unaffected. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16, or SCG 5.0 Application versions prior to 5.36.00.00, are affected. There is no sign of active exploitation: no public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.1% probability of exploitation within 30 days.
What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. In the interim, restrict network access to the gateway and limit exposure of its remote-support connections. Given the absence of known exploitation and the low EPSS score, this can be handled as routine patching, but inventory your environment to confirm which gateway form and version you run.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.