Sceawere
Vulnerability Detail
CVE-2026-79644UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Improper Certificate Validation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-295: Improper Certificate Validation
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-09-07T15:17:31.913Z",
"pubdate": "2026-09-07T15:17:31.913Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions are susceptible to an Improper Certificate Validation vulnerability. This security flaw stems from the failure of the application to properly verify the authenticity of SSL/TLS certificates during network communication.\nAn unauthenticated, remote attacker can leverage this vulnerability to perform Man-in-the-Middle (MitM) attacks. By intercepting or redirecting encrypted traffic, the attacker may bypass security mechanisms designed to protect the integrity and confidentiality of the data stream.\nSuccessful exploitation allows an adversary to gain unauthorized access to sensitive information or manipulate data exchanged between the SCG and connected endpoints. This poses a significant risk to the security posture of the infrastructure managed by the appliance.\nThe vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. There are no authentication or elevated privilege requirements for a remote attacker to initiate an exploit, provided they can position themselves within the network path.",
"technicalDetails": "The vulnerability is classified as an Improper Certificate Validation issue, where the Dell SCG appliance fails to enforce strict validation criteria when establishing secure TLS/SSL handshakes. In standard secure communication protocols, a client must verify the server's certificate against a trusted Certificate Authority (CA) and check for revocation status, validity periods, and correct hostname matching. In this implementation, the software does not sufficiently perform these checks, allowing the appliance to accept fraudulent or untrusted certificates presented by a malicious actor.\nThe attack flow initiates when an unauthenticated, remote attacker positions themselves between the Dell SCG and its intended communication peer, such as an internal management server or an external telemetry endpoint. By utilizing techniques such as ARP poisoning, DNS spoofing, or DHCP rogue server injection, the attacker intercepts the initial TLS handshake.\nWhen the SCG initiates a connection, the attacker presents a self-signed or otherwise invalid certificate. Because the underlying vulnerable library or application logic fails to validate the certificate chain, the SCG incorrectly treats the malicious certificate as trusted. This breaks the fundamental security model of the TLS protocol, enabling the attacker to establish an encrypted tunnel directly to the SCG while acting as a proxy.\nOnce the MitM position is established, the attacker gains the ability to intercept, inspect, and modify the traffic in plaintext. This facilitates unauthorized access to administrative functions, credentials, or sensitive configuration data transmitted by the SCG. The impact is significant as it compromises the confidentiality and integrity of management traffic. Furthermore, the attacker could inject malicious payloads or commands into the communication stream, potentially leading to remote code execution or further compromise of the appliance depending on the processing logic of the received data.\nThe vulnerability is persistent in Dell SCG 5.0 Appliance versions below 5.36.00.16 and Dell SCG 5.0 Application versions below 5.36.00.00. Because the appliance operates in a network-exposed environment for its core functionality, the attack surface is broad, requiring only remote connectivity to the service port. No user-level authentication or pre-existing privileged access is necessary to trigger the failure, as the validation error occurs during the automated handshake process."
}