Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper certificate validation flaw exists in Dell Secure Connect Gateway 5.0 Appliance and Application. An unauthenticated attacker with remote access can exploit the flaw, potentially allowing unauthorized connection establishment and access to the gateway. This weakness falls under CWE‑295, which centers on insufficient verification of digital certificates. The impact can include unauthorized data entry, control, or exfiltration if the attacker convinces the gateway to trust a malicious endpoint.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. The flaw is limited to the 5.0 appliance and application product lines and does not extend to newer major releases.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity. Because the EPSS score is not available, the current exploit probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote connection from an unauthenticated entity with network access to the gateway. No public exploitation is documented, but the CVSS baseline reflects the potential for significant risk.

Generated by OpenCVE AI on September 9, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Security Update for Secure Connect Gateway 5.0 via the provided KB article to correct the certificate validation flaw
  • Verify that all trusted certificates used by the gateway are issued by reputable Certificate Authorities and are not self‑signed without proper validation
  • Configure the gateway to enforce certificate pinning or strict certificate chain verification for all client connections

Generated by OpenCVE AI on September 9, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Enabling Unauthenticated Remote Access in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:24:22.395Z

Reserved: 2026-08-24T17:05:26.110Z

Link: CVE-2026-78492

cve-icon Vulnrichment

Updated: 2026-09-09T12:24:18.363Z

cve-icon NVD

Status : Received

Published: 2026-09-09T12:17:13.850

Modified: 2026-09-09T13:20:35.317

Link: CVE-2026-78492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-295

    Improper Certificate Validation