Junglewise Threat Intelligence

CVE-2026-79943: Dell Secure Connect Gateway certificate validation bypass

CVE-2026-79943 · Severity: medium · CVSS 4.8 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access appliance used to provide secure connectivity to corporate networks. This vulnerability allows unauthenticated attackers to bypass certificate validation checks, potentially enabling man-in-the-middle attacks and unauthorized access to protected resources. The flaw affects both the appliance and application versions, creating a widespread risk across deployed instances.

Technical details

The vulnerability is an improper validation of SSL/TLS certificates with host mismatch in Dell SCG 5.0. An unauthenticated attacker with network access can exploit this flaw to bypass certificate validation controls, allowing potential man-in-the-middle (MITM) attacks or spoofing of legitimate services. The vulnerable versions are Appliance prior to 5.36.00.16 and Application prior to 5.36.00.00. No special privileges or user interaction are required; the attack is remotely exploitable over the network. Patched versions address the certificate validation logic to properly verify host names and certificate chains. Dell has released updates and recommends immediate patching.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Security advisory published by Dell

References

Related threats