Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and connectivity for enterprise environments. Versions before 5.36.00.16 (appliance) and 5.36.00.00 (application) contain multiple certificate validation flaws that allow unauthenticated remote attackers to bypass security checks and gain unauthorized access to the system.
Technical details
CVE-2026-80122 and related certificate validation vulnerabilities (CVE-2026-78491, CVE-2026-79637) in Dell SCG 5.0 stem from improper validation of SSL/TLS certificates, allowing attackers to perform man-in-the-middle (MITM) attacks or bypass intended access controls. These are network-accessible vulnerabilities requiring no authentication or user interaction. An attacker with remote access can exploit these flaws to gain unauthorized access to the appliance or application. Fixes are available in SCG 5.0 Appliance version 5.36.00.16 and later, and SCG 5.0 Application version 5.36.00.00 and later.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: CVE-2026-80122 and related vulnerabilities published
- 2026-09-09: patched: Patches available: SCG 5.0 Appliance 5.36.00.16+, SCG 5.0 Application 5.36.00.00+