ZeroHour

CVE-2026-79691

large

Unauthenticated Certificate Validation Bypass in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-79691 is an improper certificate validation flaw (CWE-295) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance and the Application form factors. Because the gateway does not properly validate certificates presented by remote endpoints, an unauthenticated attacker with remote access could present a certificate the gateway wrongly accepts — typically via a machine-in-the-middle position on the gateway's network path — and bypass its certificate-based protection mechanism. Successful exploitation could allow interception or manipulation of communications between the gateway and the remote services it connects to; the CVSS 7.3 (high) score reflects low-impact losses to confidentiality, integrity, and availability. Affected deployments are SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.1% chance of exploitation within 30 days.

What to do: Upgrade to SCG 5.0 Appliance 5.36.00.16 or later and SCG 5.0 Application 5.36.00.00 or later per Dell's advisory. In the meantime, inventory deployed SCG 5.x versions (via the local management interface or SCG Policy Manager), restrict gateway network access to trusted management and connectivity paths, and monitor traffic to the remote support endpoints for signs of interception.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largelikely tens of thousands of enterprise gateway deployments (order of 10,000-100,000 sites; estimate) — SCG 5.0 is Dell's standard support-connectivity gateway, typically deployed as one or a few appliances per enterprise site or datacenter, so the large enterprise install base plausibly implies on the order of tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.