Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper certificate validation in Dell Secure Connect Gateway 5.0 Appliance and Application allows an unauthenticated attacker with remote access to bypass TLS certificate checks, potentially gaining unauthorized control over the device. The vulnerability can lead to compromise of confidentiality and integrity by enabling a man‑in‑the‑middle or spoofing attack.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. Systems running these releases should update to the recommended versions.

Risk and Exploitability

The CVSS base score of 7.7 indicates a high severity risk. EPSS is not available and the vulnerability is not listed in CISA KEV, but the lack of certificate validation means a remote, unauthenticated attacker can exploit it without needing credentials. The exploit requires only network connectivity to the appliance and involves presenting a forged certificate to the gateway, making it a significant risk for exposed environments.

Generated by OpenCVE AI on September 9, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell Secure Connect Gateway 5.0 Security Update DSA-2026-382 to upgrade the appliance to 5.36.00.16 and the application to 5.36.00.00 or later.
  • After applying the update, ensure that the gateway enforces strict certificate validation and rejects self‑signed or otherwise untrusted certificates.
  • If an immediate update cannot be performed, disable remote management access to the SCG appliance from untrusted networks and apply network segmentation or firewall rules to restrict traffic to trusted sources only.

Generated by OpenCVE AI on September 9, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Enables Remote Unauthorized Access in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:54:54.453Z

Reserved: 2026-08-25T10:35:45.860Z

Link: CVE-2026-79637

cve-icon Vulnrichment

Updated: 2026-09-09T12:54:50.146Z

cve-icon NVD

Status : Received

Published: 2026-09-09T12:17:13.977

Modified: 2026-09-09T13:20:37.097

Link: CVE-2026-79637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-295

    Improper Certificate Validation