Executive brief
Dell Secure Connect Gateway is a VPN/remote access appliance used to provide secure connections to corporate networks. A vulnerability in certificate validation could allow unauthenticated attackers with remote access to bypass security controls and gain unauthorized access to the gateway or perform server-side request forgery attacks against internal systems.
Technical details
Dell SCG versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain improper certificate validation (CVE-2026-79975), allowing unauthenticated remote attackers to bypass SSL/TLS validation controls. The vulnerability enables attackers to intercept, manipulate, or forge secure communications without proper certificate verification. With remote network access and no authentication required, an attacker can execute server-side request forgery attacks or perform man-in-the-middle attacks against the affected gateway. Patches are available in the versions specified above.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed