Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-07
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability reflects an improper certificate validation flaw in Dell Secure Connect Gateway 5.0. An attacker who can reach the device’s management interface from outside the network does not need existing credentials to exploit the weakness, allowing unauthorized authentication or session takeover once the certificate check is bypassed. The flaw jeopardizes the confidentiality and integrity of protected traffic handled by the gateway and enables potential lateral movement within the protected network.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are susceptible.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. EPSS information is currently unavailable, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack requires remote connectivity but not authentication, so any external host with network access to the gateway’s management interface may attempt exploitation. Inferred from the description that the vector is remote, and an unauthenticated user can trigger it.

Generated by OpenCVE AI on September 7, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Appliance to version 5.36.00.16 or later, and the Application to version 5.36.00.00 or later, as indicated by Dell’s security advisory.
  • Restrict external network access to the Secure Connect Gateway’s management interface by applying firewall rules or network segmentation to limit exposure to trusted sources.
  • If an upgrade cannot be performed immediately, disable or block remote management ports for non‑essential services and enforce strong authentication for remaining access points.
  • Continuously monitor authentication logs for unusual or repeated access attempts that may indicate exploitation attempts.

Generated by OpenCVE AI on September 7, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway Allowing Unauthorized Remote Access

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T14:08:48.895Z

Reserved: 2026-08-25T10:35:45.861Z

Link: CVE-2026-79644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T15:17:31.913

Modified: 2026-09-07T15:17:31.913

Link: CVE-2026-79644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:30:06Z

Weaknesses
  • CWE-295

    Improper Certificate Validation