Executive brief
Dell Secure Connect Gateway is a remote access appliance used to provide secure connectivity to corporate networks. The improper certificate validation vulnerability allows an unauthenticated attacker with network access to bypass security controls and gain unauthorized access to the system, potentially compromising connected network resources.
Technical details
This is an improper certificate validation vulnerability in Dell SCG 5.0 affecting Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can exploit this by presenting invalid or untrusted certificates that the application fails to properly validate, enabling man-in-the-middle attacks or unauthorized access. No authentication is required and the attack is network-reachable. The vulnerability allows attackers to bypass intended certificate verification mechanisms and gain unauthorized access to the system. Patches are available in SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: Published in NVD
- 2026-09-07: patched: Patches available: SCG 5.0 Appliance 5.36.00.16, SCG 5.0 Application 5.36.00.00