Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Certificate Validation flaw in Dell Secure Connect Gateway 5.0 that allows an attacker without prior authentication, but with remote network access, to potentially subvert the SSL/TLS handshake. By accepting a forged or invalid certificate, the attacker may gain unauthorized access to encrypted traffic, compromising the confidentiality and integrity of the data communicated through the gateway.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. No other vendors are listed as impacted.

Risk and Exploitability

The CVSS score of 3.7 indicates a low‑to‑moderate severity. EPSS data is unavailable, and the vulnerability is not included in CISA’s KEV list. The exploit requires remote network access but no authentication, suggesting a network‑based attack path. While the low CVSS score reflects limited impact compared to other flaws, the ability to bypass certificate validation still enables an attacker to intercept or modify traffic, making the risk non‑negligible. Organizations should consider the potential for advanced persistent threats or targeted attacks when evaluating the threat.

Generated by OpenCVE AI on September 9, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Secure Connect Gateway Appliance to version 5.36.00.16 or later.
  • Upgrade the Secure Connect Gateway Application to version 5.36.00.00 or later.
  • After updating, verify that the gateway correctly validates certificates on all inbound connections.

Generated by OpenCVE AI on September 9, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T15:56:32.782Z

Reserved: 2026-08-25T12:04:33.630Z

Link: CVE-2026-79690

cve-icon Vulnrichment

Updated: 2026-09-09T15:56:29.043Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-09T15:17:09.830

Modified: 2026-09-09T16:17:07.320

Link: CVE-2026-79690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:45:13Z

Weaknesses
  • CWE-295

    Improper Certificate Validation