CVE-2026-79734
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
CVE-2026-79734 is an improper certificate validation flaw (CWE-295) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance form factor (versions prior to 5.36.00.16) and the Application form factor (versions prior to 5.36.00.00). Because the gateway fails to properly validate TLS certificates, an unauthenticated remote attacker positioned on the network path can impersonate a trusted endpoint (such as Dell's cloud services) and tamper with gateway communications, achieving a protection mechanism bypass. The CVSS 3.1 score of 7.5 (High) reflects a network-exploitable, low-complexity attack with no privileges or user interaction required, and a high impact to integrity with no confidentiality or availability loss. Organizations running SCG 5.0 to connect their Dell hardware to Dell remote support and telemetry services are affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later per Dell's advisory. Until patched, review whether the gateway's network path can be reached by unauthenticated remote attackers and restrict exposure at the network edge. Because the flaw is a certificate validation bypass, also monitor gateway-to-Dell-service traffic for signs of interception or tampering.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.