Description
Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-09
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper certificate validation flaw in Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.xx. It permits an attacker to bypass the gateway’s protection mechanisms by forging or accepting invalid certificates, potentially enabling unauthorized network access or traffic manipulation. The weakness arises from the application’s failure to enforce strict certificate checks during TLS handshakes.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance and Application are impacted. All builds of version 5.0 below 5.36.00.xx are vulnerable, typically deployed on Dell secure gateway appliances that expose remote management interfaces for connectivity. No other vendors or product lines are listed as affected.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and no EPSS score is available, suggesting limited evidence of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector involves remote access through exposed management or communication channels, allowing an unauthenticated attacker to bypass security checks. While the exploit does not compromise local credentials, it undermines gateway confinement and could facilitate further lateral movement within the protected network.

Generated by OpenCVE AI on September 9, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Dell Secure Connect Gateway appliance to version 5.36.00.xx or a later release that fixes the certificate validation flaw
  • If immediate upgrading is not possible, restrict remote access to the gateway or place the device behind an internal firewall and limit user privileges until remediation is applied
  • After applying the update, verify that the gateway enforces strict certificate validation by testing TLS handshakes against trusted certificates and ensuring that invalid or self‑signed certificates are rejected

Generated by OpenCVE AI on September 9, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0 Leads to Protection Bypass

Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:11:01.638Z

Reserved: 2026-08-25T14:04:56.065Z

Link: CVE-2026-79732

cve-icon Vulnrichment

Updated: 2026-09-09T16:10:56.359Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T15:17:10.100

Modified: 2026-09-09T20:02:19.957

Link: CVE-2026-79732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:00:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation