Executive brief
Dell Secure Connect Gateway (SCG) is a virtual appliance and application used to provide secure remote access to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain an improper certificate validation vulnerability that allows unauthenticated remote attackers to bypass security protections and potentially gain unauthorized access to the system.
Technical details
The vulnerability is a CWE-295 improper certificate validation flaw in Dell SCG 5.0 that allows an unauthenticated attacker with network access to exploit insufficient certificate verification mechanisms. The root cause is inadequate validation of TLS/SSL certificates, enabling attackers to bypass authentication and authorization controls. No authentication or user interaction is required; an attacker can remotely exploit this over the network. Successful exploitation leads to unauthorized access and potential compromise of the gateway. Patches are available: Dell SCG 5.0 Appliance version 5.36.00.16 and Dell SCG 5.0 Application version 5.36.00.00 or later.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: CVE-2026-78483 published
- 2026-09-09: patched: Patches available: SCG 5.0 Appliance 5.36.00.16+, SCG 5.0 Application 5.36.00.00+