Executive brief
Dell Secure Connect Gateway is a network appliance and application used to provide secure remote connectivity and access management. This vulnerability allows an unauthenticated attacker with remote network access to bypass security protections by exploiting improper certificate validation, potentially enabling unauthorized access and man-in-the-middle attacks.
Technical details
This is an improper certificate validation vulnerability (CWE-295) in Dell Secure Connect Gateway 5.0. An unauthenticated attacker with remote network access can exploit this flaw to bypass the protection mechanisms that depend on certificate validation. The vulnerability allows an attacker to circumvent SSL/TLS certificate checks, enabling man-in-the-middle attacks, session hijacking, or unauthorized access to critical gateway functions. No authentication or user interaction is required. Dell has released patched versions (5.36.00.16 for Appliance and 5.36.00.00 for Application) that customers should deploy immediately.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Dell released security update DSA-2026-382 with patched versions