Junglewise Threat Intelligence

CVE-2026-79970: Dell Secure Connect Gateway improper verification of cryptographic signature

CVE-2026-79970 · Severity: medium · CVSS 5.6 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a remote access appliance used by enterprises to provide secure connectivity. A cryptographic signature verification flaw allows unauthenticated remote attackers to bypass protection mechanisms, potentially gaining unauthorized access to network resources protected by the gateway.

Technical details

The vulnerability is an improper verification of cryptographic signature in Dell SCG 5.0, affecting both the Appliance and Application components. An unauthenticated attacker with network access can exploit this flaw to bypass the gateway's protection mechanisms by presenting forged or unverified cryptographic signatures. The attack requires no authentication, user interaction, or special complexity—any remote attacker can trigger the vulnerability. Successful exploitation could lead to unauthorized access to systems behind the gateway. Dell has released patched versions (Appliance 5.36.00.16 and Application 5.36.00.00) to correct the signature verification logic.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-79970 publicly disclosed
  • 2026-09-09: patched: Patches available: Appliance version 5.36.00.16, Application version 5.36.00.00

References

Related threats