Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability permits an attacker to bypass TLS hostname verification by supplying a forged certificate that appears to match the expected identity, allowing the attacker to establish a trusted session with the gateway without authentication and gain unauthorized access to the device's management interface and potentially the connected network.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. Newer releases of these products incorporate the certificate validation fix.

Risk and Exploitability

The CVSS score of 7.0 reflects medium severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, so the exploitation likelihood is unknown at present. An unauthenticated attacker with remote network access can exploit the flaw by presenting a forged certificate during the TLS handshake, leveraging the lack of hostname validation to establish a privileged session.

Generated by OpenCVE AI on September 9, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell Security Advisory DSA-2026-382 to upgrade the appliance to version 5.36.00.16 and the application to version 5.36.00.00, which corrects the certificate validation issue.
  • Reconfigure the gateway to enforce strict TLS hostname verification, ensuring that client certificates must match the expected hostnames and preventing forged certificates from being accepted.
  • If a patch cannot be applied immediately, temporarily disable external inbound TLS interfaces or apply strict ingress filtering to block untrusted connections until the vulnerability is mitigated.

Generated by OpenCVE AI on September 9, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Improper TLS Certificate Validation with Host Mismatch in Dell Secure Connect Gateway

Wed, 09 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-297
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:59:57.238Z

Reserved: 2026-08-25T10:35:45.859Z

Link: CVE-2026-79636

cve-icon Vulnrichment

Updated: 2026-09-09T12:59:53.601Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T08:17:22.133

Modified: 2026-09-09T20:17:03.783

Link: CVE-2026-79636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch