Executive brief
Dell Secure Connect Gateway (SCG) is a VPN/remote access appliance used to securely connect users to corporate networks. Versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) fail to properly validate SSL/TLS certificates, allowing an unauthenticated attacker to intercept and manipulate encrypted connections. An attacker could impersonate legitimate servers or eavesdrop on sensitive communications without requiring any credentials or user interaction.
Technical details
This vulnerability is a certificate validation flaw where the application does not properly verify that the presented certificate matches the hostname being accessed (host mismatch validation). The root cause is improper validation logic in the SSL/TLS certificate verification code, likely failing to check the Common Name (CN) or Subject Alternative Name (SAN) fields against the destination hostname. An unauthenticated remote attacker can exploit this via network access by performing a man-in-the-middle (MITM) attack with an arbitrary certificate. The impact is unauthorized access and potential credential theft, as encrypted sessions can be intercepted. Dell has released patched versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to address this issue.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed