CVE-2026-80164
largeUnauthenticated certificate validation flaw in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway 5.0 contains an improper certificate validation flaw (CWE-295) in which the appliance or application fails to adequately verify TLS certificates. An unauthenticated attacker with remote network access could potentially exploit this, for example by impersonating a trusted endpoint or intercepting the gateway's TLS communications, leading to unauthorized access with high impact to confidentiality and integrity (CVSS 3.1: 9.1, no availability impact). Organizations running Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 or Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation is reported, and the EPSS score of 0.1% (4th percentile) indicates a low near-term probability of exploitation.
What to do: Upgrade Dell Secure Connect Gateway 5.0 Appliance to version 5.36.00.16 or later, and the Application to version 5.36.00.00 or later. In the meantime, restrict network access to the gateway's management interface and ensure it communicates only over trusted network paths, since exploitation requires remote network reachability. Check your deployed version in the appliance/application administration UI and monitor Dell's security advisory for this CVE.
| Dell Secure Connect Gateway 5.0 Appliance | All versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | All versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.