Executive brief
Dell Secure Connect Gateway is a network access control appliance used to manage secure remote connections and protect network perimeters. The improper certificate validation vulnerability allows remote attackers to bypass security controls and gain unauthorized access to the system without authentication, potentially enabling lateral movement into protected networks.
Technical details
CVE-2026-79639 is an improper certificate validation vulnerability in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance (before 5.36.00.16) and Application (before 5.36.00.00) components. An unauthenticated remote attacker can exploit this flaw by sending specially crafted requests that bypass certificate validation checks, leading to unauthorized access. The vulnerability requires only network reachability with no authentication or user interaction. A patch is available through Dell's security update DSA-2026-382.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: DSA-2026-382 security update available