Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-09
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway versions prior to the specified updates contain a flaw that allows an attacker to exploit improper validation of certificates. This weakness can lead to the bypass of security controls, potentially giving attackers unauthorized access or the ability to tamper with protected communications. The impact is focused on integrity and confidentiality of data exchanged through the gateway, as the attacker may impersonate trusted endpoints or evade authentication checks.

Affected Systems

The vulnerability affects Dell Secure Connect Gateway Appliance version 5.0 prior to 5.36.00.16 and Dell Secure Connect Gateway Application version 5.0 prior to 5.36.00.00. Systems running any earlier release of these components are potentially exposed.

Risk and Exploitability

The flaw is rated with a CVSS score of 5.9, indicating medium severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack vector is remote, with an attacker needing only network access to the gateway; authentication is not required. Exploitation would involve presenting a forged or manipulated certificate to the gateway to gain privileged actions or modify traffic, thereby bypassing built-in protection mechanisms.

Generated by OpenCVE AI on September 9, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later. 1.
  • Update Dell Secure Connect Gateway Application to version 5.36.00.00 or later. 2.
  • If an immediate update is not possible, restrict external network access to the gateway by configuring firewall rules to allow traffic only from trusted IP addresses and disable any unused remote management interfaces. 3.

Generated by OpenCVE AI on September 9, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:01:15.784Z

Reserved: 2026-08-24T17:05:26.110Z

Link: CVE-2026-78489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T12:17:13.593

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-78489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:00:14Z

Weaknesses
  • CWE-295

    Improper Certificate Validation