Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance that manages secure connections for corporate networks. An improper certificate validation flaw allows remote attackers to bypass security checks and gain unauthorized access without authentication, potentially compromising network security and enabling further intrusion.
Technical details
CVE-2026-79644 involves improper certificate validation in Dell SCG 5.0, affecting both the appliance and application variants. An unauthenticated remote attacker can exploit this vulnerability to bypass certificate validation controls, allowing man-in-the-middle attacks or unauthorized access to the system. The vulnerability requires network access but no authentication or user interaction. Affected versions include Appliance prior to 5.36.00.16 and Application prior to 5.36.00.00; patched versions are available from Dell.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed
- 2026-09-07: advisory: DSA-2026-382 published with multiple vulnerabilities