ZeroHour

CVE-2026-80164

large

Unauthenticated certificate validation flaw in Dell Secure Connect Gateway 5.0

CVSS 3.1
9.1 critical
EPSS
<1%p5
Published
()
Modified
AI analysis

Dell Secure Connect Gateway 5.0 contains an improper certificate validation flaw (CWE-295) in which the appliance or application fails to adequately verify TLS certificates. An unauthenticated attacker with remote network access could potentially exploit this, for example by impersonating a trusted endpoint or intercepting the gateway's TLS communications, leading to unauthorized access with high impact to confidentiality and integrity (CVSS 3.1: 9.1, no availability impact). Organizations running Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 or Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation is reported, and the EPSS score of 0.1% (4th percentile) indicates a low near-term probability of exploitation.

What to do: Upgrade Dell Secure Connect Gateway 5.0 Appliance to version 5.36.00.16 or later, and the Application to version 5.36.00.00 or later. In the meantime, restrict network access to the gateway's management interface and ensure it communicates only over trusted network paths, since exploitation requires remote network reachability. Check your deployed version in the appliance/application administration UI and monitor Dell's security advisory for this CVE.

Affected
Dell Secure Connect Gateway 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
large≈ tens of thousands of enterprise installations worldwide (estimate; no public install counts) — Secure Connect Gateway is Dell's standard on-premises connectivity component for enterprise SupportAssist deployments, so a rough order-of-magnitude estimate of tens of thousands of installations is inferred from Dell's enterprise install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.