Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 contains an Improper Certificate Validation flaw that allows a remote, unauthenticated attacker to bypass certificate checks and gain unauthorized access to the appliance or application. This weakness (CWE‑295) can be used to impersonate trusted connections, potentially exposing sensitive management interfaces and network traffic.

Affected Systems

Versions of Dell Secure Connect Gateway Appliance 5.0 earlier than 5.36.00.16 and versions of Dell Secure Connect Gateway Application 5.0 earlier than 5.36.00.00 are vulnerable. The flaw exists in both the appliance and application components of the gateway.

Risk and Exploitability

The vulnerability has a CVSS score of 7.4, indicating a high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker with network access to the gateway can exploit the certificate validation weakness without prior authentication, leading to unauthorized control of the system.

Generated by OpenCVE AI on September 9, 2026 at 10:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Secure Connect Gateway to the latest public security update that brings appliance versions to at least 5.36.00.16 and application versions to at least 5.36.00.00.
  • Verify that the gateway is configured to enforce strict certificate validation and that all certificates presented to the system originate from trusted authorities.
  • Restrict remote management traffic to the gateway by using firewall or segmentation rules to allow connections only from authorized management IP addresses.

Generated by OpenCVE AI on September 9, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0 Allowing Remote Unauthorized Access

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T08:07:26.877Z

Reserved: 2026-08-24T17:05:26.110Z

Link: CVE-2026-78494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T09:17:10.990

Modified: 2026-09-09T09:17:10.990

Link: CVE-2026-78494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:15:09Z

Weaknesses
  • CWE-295

    Improper Certificate Validation