Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell Secure Connect Gateway Policy Manager versions before 5.34.00.16 contain an Improper Certificate Validation flaw. This weakness allows an unauthenticated attacker with network access to trick the system into accepting a forged certificate, which can lead to denial of service, information disclosure, and potentially remote code execution. The described impact is consistent with CWE‑295, highlighting a failure in validating cryptographic certificates.

Affected Systems

Dell Secure Connect Gateway Policy Manager is the affected product. Vulnerable releases are all versions prior to 5.34.00.16. No further sub‑versions are listed. Users running affected builds should verify that they are deployed with the latest 5.34.00.16 or later release.

Risk and Exploitability

The CVSS score of 7.5 marks the issue as High severity, while the EPSS score is not available, indicating insufficient publicly documented exploit data. The vulnerability is not in the CISA KEV catalog, suggesting it has not been publicly exploited yet. An attacker would need remote connectivity to the management interface, with no authentication, to leverage the certificate issue. If successful, the attacker could disrupt services, extract sensitive information, or execute arbitrary commands on the SCG appliance.

Generated by OpenCVE AI on October 9, 2026 at 10:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Policy Manager to version 5.34.00.16 or later.
  • Restrict network access to the SCG management interface with firewall or VLAN segmentation.
  • Enable logging of certificate validation failures and monitor for anomalous behaviour.

Generated by OpenCVE AI on October 9, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell SCG Policy Manager Enables Remote Exploitation

Fri, 09 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-09T08:51:14.757Z

Reserved: 2026-08-21T23:04:41.426Z

Link: CVE-2026-78020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:09.300

Modified: 2026-10-09T09:17:09.300

Link: CVE-2026-78020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:45:05Z

Weaknesses
  • CWE-295

    Improper Certificate Validation