CVE-2026-79691
largeUnauthenticated Certificate Validation Bypass in Dell Secure Connect Gateway 5.0
CVE-2026-79691 is an improper certificate validation flaw (CWE-295) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance and the Application form factors. Because the gateway does not properly validate certificates presented by remote endpoints, an unauthenticated attacker with remote access could present a certificate the gateway wrongly accepts — typically via a machine-in-the-middle position on the gateway's network path — and bypass its certificate-based protection mechanism. Successful exploitation could allow interception or manipulation of communications between the gateway and the remote services it connects to; the CVSS 7.3 (high) score reflects low-impact losses to confidentiality, integrity, and availability. Affected deployments are SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.1% chance of exploitation within 30 days.
What to do: Upgrade to SCG 5.0 Appliance 5.36.00.16 or later and SCG 5.0 Application 5.36.00.00 or later per Dell's advisory. In the meantime, inventory deployed SCG 5.x versions (via the local management interface or SCG Policy Manager), restrict gateway network access to trusted management and connectivity paths, and monitor traffic to the remote support endpoints for signs of interception.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.