Executive brief
Dell Secure Connect Gateway is a remote access appliance and application used to securely connect users to corporate networks. This vulnerability allows an unauthenticated attacker to bypass certificate validation and gain unauthorized access to the system, potentially compromising network security and exposing sensitive business data.
Technical details
This is an improper certificate validation vulnerability in Dell Secure Connect Gateway 5.0 that affects both the Appliance (versions prior to 5.36.00.16) and Application (versions prior to 5.36.00.00). An unauthenticated remote attacker can exploit this flaw by sending specially crafted requests that bypass certificate verification mechanisms. The vulnerability allows attackers to intercept and manipulate communications or gain unauthorized access to the system without proper authentication. No user interaction is required, and the vulnerability is remotely exploitable over the network. Dell has released patches addressing this issue in the specified patched versions.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Patches available in SCG Appliance 5.36.00.16 and Application 5.36.00.00