ZeroHour

CVE-2026-79734

large

Improper Certificate Validation in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.5 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-79734 is an improper certificate validation flaw (CWE-295) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance form factor (versions prior to 5.36.00.16) and the Application form factor (versions prior to 5.36.00.00). Because the gateway fails to properly validate TLS certificates, an unauthenticated remote attacker positioned on the network path can impersonate a trusted endpoint (such as Dell's cloud services) and tamper with gateway communications, achieving a protection mechanism bypass. The CVSS 3.1 score of 7.5 (High) reflects a network-exploitable, low-complexity attack with no privileges or user interaction required, and a high impact to integrity with no confidentiality or availability loss. Organizations running SCG 5.0 to connect their Dell hardware to Dell remote support and telemetry services are affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later per Dell's advisory. Until patched, review whether the gateway's network path can be reached by unauthenticated remote attackers and restrict exposure at the network edge. Because the flaw is a certificate validation bypass, also monitor gateway-to-Dell-service traffic for signs of interception or tampering.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largeplausibly tens of thousands of enterprise gateway deployments (estimate; no public counts in the source data) — SCG is typically deployed one gateway per customer site to provide SupportAssist/remote-support connectivity for Dell hardware, so the affected base is inferred from Dell's large enterprise install base and per-site deployment pattern…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.