Executive brief
Dell Secure Connect Gateway is a remote access appliance and application that manages secure connections to corporate networks. An improper certificate validation vulnerability allows unauthenticated remote attackers to bypass security controls and gain unauthorized access to the system, potentially leading to data theft or network compromise.
Technical details
The vulnerability is an improper certificate validation flaw in Dell Secure Connect Gateway (SCG) 5.0 that allows unauthenticated attackers with network access to bypass certificate validation checks. The root cause lies in insufficient validation of SSL/TLS certificates during critical authentication or secure communication flows. An attacker can exploit this by intercepting network traffic or presenting invalid certificates, allowing them to establish unauthorized connections without proper credential verification. The attack requires no authentication, user interaction, or special privileges. Dell has released patched versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to address this vulnerability.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed