Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance used to provide secure connectivity to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain improper certificate validation that allows unauthenticated remote attackers to bypass security checks and gain unauthorized access to the system.
Technical details
The vulnerability is an improper certificate validation flaw in Dell Secure Connect Gateway that allows an unauthenticated attacker with remote network access to exploit the weakness. The root cause stems from insufficient validation of SSL/TLS certificates during authentication or connection establishment. By exploiting this vulnerability, an attacker can perform man-in-the-middle attacks or bypass certificate pinning mechanisms to gain unauthorized access. The vulnerability affects appliance versions prior to 5.36.00.16 and application versions prior to 5.36.00.00; patches are available and Dell recommends immediate upgrade.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed