CVE-2026-80122
largeImproper Certificate Validation in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains an improper certificate validation flaw (CWE-295), meaning the gateway does not correctly verify TLS certificate identity during its network communications. An unauthenticated attacker with remote access who can position themselves in the communication path (for example, via a man-in-the-middle position or by presenting a crafted certificate) could exploit this to gain unauthorized access to the gateway or the traffic it handles. The flaw affects both the SCG 5.0 Appliance and the SCG 5.0 Application deployments across the affected version ranges, and it carries a CVSS 3.1 base score of 7.3 (high) with network reachability, low attack complexity, and no privileges or user interaction required. Organizations of any size that run Dell's support-connectivity gateway to link their Dell infrastructure to Dell support services are potentially affected. There is currently no evidence of active exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later, since these are the first versions listed as resolving the flaw. In the meantime, restrict network access to the gateway, limit its outbound paths, and inspect network paths between the gateway and Dell endpoints for potential interception points. No public exploit is known, so there is no immediate evidence of in-the-wild attacks, but patching should be prioritized given the unauthenticated, network-reachable nature of the issue.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.