Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Certificate Validation flaw that allows a remote attacker to bypass the security mechanisms of Dell Secure Connect Gateway 5.0. If exploited, the attacker can present a forged or otherwise non‑trusted certificate and gain privileged access or modify connections, thereby compromising confidentiality and integrity of the system. The weakness is identified as CWE‑295.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Users of these product lines should verify their current build against these baseline versions.

Risk and Exploitability

The CVSS score of 5.9 indicates medium severity. No EPSS score is available, and the issue is not listed in CISA KEV. Based on the description, the attack vector is inferred to be unauthenticated remote access; an attacker can trigger the flaw over the public interface without needing credentials. The risk is moderate with no evidence of widespread exploitation to date.

Generated by OpenCVE AI on September 7, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway to version 5.36.00.16 for the appliance or 5.36.00.00 for the application to obtain the vendor patch that implements proper certificate validation.
  • After patching, verify that all certificates presented by the gateway are signed by a trusted authority and that no self‑signed or expired certificates are accepted.
  • Limit remote access to the gateway using network segmentation or firewall rules to reduce the exposure of the interface vulnerable to unauthenticated requests.

Generated by OpenCVE AI on September 7, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0 Allows Remote Bypass

Mon, 07 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T13:48:38.662Z

Reserved: 2026-08-25T14:04:56.065Z

Link: CVE-2026-79734

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T14:16:54.460

Modified: 2026-09-07T14:16:54.460

Link: CVE-2026-79734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation