Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-07
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 Appliance and Application prior to specific releases contain a certificate validation flaw that permits an attacker who can reach the system remotely without authentication to bypass normal certificate checks and gain unauthorized access. The vulnerability is directly tied to the weaknesses identified as CWE‑295, where the software does not properly validate certificates presented during secure communications. The resulting unauthorized access could undermine the confidentiality and integrity of the secure connections that the appliance and application provide, allowing an attacker to potentially impersonate a trusted partner or manipulate data in transit.

Affected Systems

The affected systems are Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. The vulnerability applies to all deployments of these early releases, regardless of deployment environment, as the flawed certificate validation logic is embedded in the core gateway software.

Risk and Exploitability

The CVSS score of 5.6 indicates a moderate severity, and no EPSS data is available, so the exploitation probability is unknown. The vulnerability is listed as not in the CISA KEV catalog, suggesting no known publicly available exploits. Based on the description, an unauthenticated attacker who can reach the gateway remotely could exploit the flaw, achieving unauthorized access to clear or tamper with secure tunnels set up by the gateway.

Generated by OpenCVE AI on September 7, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Appliance to version 5.36.00.16 or later, and the Application to version 5.36.00.00 or later, following Dell’s official update instructions.
  • Apply the Dell Secure Update for Secure Connect Gateway (as referenced in the Dell KB article) to deploy the latest security fix.
  • Verify that the gateway’s certificate chains are correctly configured and that only trusted certificates are accepted.
  • If immediate patching is infeasible, restrict remote access to the gateway through firewall rules or network segmentation to limit the attack surface.

Generated by OpenCVE AI on September 7, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Permitting Unauthorized Remote Access in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T15:55:19.173Z

Reserved: 2026-08-25T10:35:45.860Z

Link: CVE-2026-79642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T16:17:29.197

Modified: 2026-09-07T16:17:29.197

Link: CVE-2026-79642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation