Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-09
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Protection Bypass via Improper Certificate Validation
Action: Patch Immediately
AI Analysis

Impact

An unnamed vulnerability has been identified in Dell Secure Connect Gateway 5.0 that allows an attacker to bypass protection mechanisms by exploiting improper certificate validation. The flaw permits an unauthenticated entity with remote access to supply a forged or otherwise invalid certificate and have it accepted, potentially allowing the attacker to establish a connection that is otherwise restricted. This could lead to confidentiality or integrity compromise of communication channels or services that rely on the gateway for secure access.

Affected Systems

The issue affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Systems running these specific older releases are vulnerable, while newer versions released after those dates contain the fix.

Risk and Exploitability

The CVSS score of 5.6 indicates a medium severity level. Exploitation can be achieved by an unauthenticated attacker with remote access, and no password or privileged credentials are required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it has not yet been widely exploited in the wild. Nonetheless, the remote nature of the attack and the absence of authentication make it a realistic risk for exposed gateway deployments.

Generated by OpenCVE AI on September 9, 2026 at 10:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Dell Secure Connect Gateway Appliance to at least version 5.36.00.16 and the Application to at least 5.36.00.00 as distributed by Dell.
  • Ensure the newer firmware or patches enforce strict TLS/SSL certificate validation and disallow self‑signed or expired certificates.
  • Limit remote access to the gateway to trusted IP addresses and monitor TLS session logs for anomalous certificate usage.

Generated by OpenCVE AI on September 9, 2026 at 10:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway 5.0 Allows Remote Protection Bypass

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:01:51.820Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79967

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:46.708Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T09:17:11.360

Modified: 2026-09-09T19:45:30.983

Link: CVE-2026-79967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation