Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 contains an Improper Certificate Validation flaw that allows a remote, unauthenticated attacker to bypass certificate checks and gain unauthorized access to the appliance or application. This weakness (CWE‑295) can be used to impersonate trusted connections, potentially exposing sensitive management interfaces and network traffic.

Affected Systems

Versions of Dell Secure Connect Gateway Appliance 5.0 earlier than 5.36.00.16 and versions of Dell Secure Connect Gateway Application 5.0 earlier than 5.36.00.00 are vulnerable. The flaw exists in both the appliance and application components of the gateway.

Risk and Exploitability

The vulnerability has a CVSS score of 7.4, indicating a high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker with network access to the gateway can exploit the certificate validation weakness without prior authentication, leading to unauthorized control of the system.

Generated by OpenCVE AI on September 9, 2026 at 10:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Secure Connect Gateway to the latest public security update that brings appliance versions to at least 5.36.00.16 and application versions to at least 5.36.00.00.
  • Verify that the gateway is configured to enforce strict certificate validation and that all certificates presented to the system originate from trusted authorities.
  • Restrict remote management traffic to the gateway by using firewall or segmentation rules to allow connections only from authorized management IP addresses.

Generated by OpenCVE AI on September 9, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0 Allowing Remote Unauthorized Access

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T03:56:30.743Z

Reserved: 2026-08-24T17:05:26.110Z

Link: CVE-2026-78494

cve-icon Vulnrichment

Updated: 2026-09-09T15:41:28.467Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T09:17:10.990

Modified: 2026-09-11T04:17:52.557

Link: CVE-2026-78494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:05Z

Weaknesses
  • CWE-295

    Improper Certificate Validation