Executive brief
Dell Secure Connect Gateway (SCG) is an appliance that provides secure remote access to corporate networks. A vulnerability in certificate validation could allow an attacker to bypass security checks and gain unauthorized access to protected systems, potentially compromising sensitive data or network integrity.
Technical details
Dell SCG 5.0 Appliance contains an improper certificate validation vulnerability (CVE-2026-79732) in its TLS/SSL certificate handling. An unauthenticated attacker with network access can exploit this flaw to bypass certificate verification mechanisms, potentially enabling man-in-the-middle attacks or spoofing of trusted endpoints. The vulnerability requires no authentication, user interaction, or special privileges. An attacker could exploit this to redirect traffic, intercept communications, or gain unauthorized access to gateway functions. Remediation is available by upgrading to version 5.36.00.xx or later.
Affected products
- Dell Secure Connect Gateway (SCG) 5.0 Appliance prior to 5.36.00.xx
Timeline
- 2026-09-09: disclosed