ZeroHour

CVE-2026-80122

large

Improper Certificate Validation in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
<1%p3
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains an improper certificate validation flaw (CWE-295), meaning the gateway does not correctly verify TLS certificate identity during its network communications. An unauthenticated attacker with remote access who can position themselves in the communication path (for example, via a man-in-the-middle position or by presenting a crafted certificate) could exploit this to gain unauthorized access to the gateway or the traffic it handles. The flaw affects both the SCG 5.0 Appliance and the SCG 5.0 Application deployments across the affected version ranges, and it carries a CVSS 3.1 base score of 7.3 (high) with network reachability, low attack complexity, and no privileges or user interaction required. Organizations of any size that run Dell's support-connectivity gateway to link their Dell infrastructure to Dell support services are potentially affected. There is currently no evidence of active exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later, since these are the first versions listed as resolving the flaw. In the meantime, restrict network access to the gateway, limit its outbound paths, and inspect network paths between the gateway and Dell endpoints for potential interception points. No public exploit is known, so there is no immediate evidence of in-the-wild attacks, but patching should be prioritized given the unauthenticated, network-reachable nature of the issue.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largelikely on the order of tens of thousands of enterprise deployments (estimate; no public scan data available) — Dell SCG is the vendor's standard support-connectivity component widely deployed at enterprise and datacenter sites running Dell infrastructure, suggesting deployments plausibly number in the tens of thousands, though most sit on internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.