Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper certificate validation flaw in Dell Secure Connect Gateway 5.0 Appliance and Application allows an unauthenticated attacker with remote access to bypass security checks, potentially gaining unauthorized access to system resources. Because the vulnerability directly undermines transmission integrity and authentication guarantees, it can expose sensitive configuration data, compromise network traffic, or provide a foothold for further attacks. The weakness arises from failure to verify digital certificates as required by standard TLS rules, thereby enabling man‑in‑the‑middle or spoofing attacks.

Affected Systems

The flaw affects all Dell Secure Connect Gateway 5.0 Appliance builds earlier than version 5.36.00.16 and all 5.0 Application builds earlier than 5.36.00.00. These products provide secure connectivity for enterprise networks and are typically deployed on‑premise or as virtual appliances, meaning that vulnerability exposure could impact a broad range of deployment scenarios.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. No EPSS metric is available, but the flaw is exploitable remotely without authentication, meaning attackers could potentially gain privileged access or disrupt connectivity. Although not yet listed in CISA's KEV catalog, the lack of current public exploits does not diminish the criticality of addressing the vulnerability promptly.

Generated by OpenCVE AI on September 9, 2026 at 10:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Dell Secure Connect Gateway 5.0 Appliance version 5.36.00.16 or newer to patch the certificate validation flaw.
  • Upgrade to Dell Secure Connect Gateway 5.0 Application version 5.36.00.00 or newer.
  • If an immediate upgrade is not possible, implement network segmentation and restrict inbound connections to the gateway to trusted IP ranges only.
  • Enable stringent certificate validation policies on the gateway, ensuring only certificates from trusted authorities are accepted and removing any unnecessary self‑signed certificates.

Generated by OpenCVE AI on September 9, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell Secure Connect Gateway Allows Unauthorized Remote Access

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T13:01:24.558Z

Reserved: 2026-08-25T20:04:12.993Z

Link: CVE-2026-80122

cve-icon Vulnrichment

Updated: 2026-09-09T13:01:20.703Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T09:17:12.303

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-80122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:15:09Z

Weaknesses
  • CWE-295

    Improper Certificate Validation