Sceawere
Vulnerability Detail
CVE-2026-79691UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Improper Certificate Validation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-295: Improper Certificate Validation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-07T16:17:29.440Z",
"pubdate": "2026-09-07T16:17:29.440Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 is susceptible to an Improper Certificate Validation vulnerability due to failures in verifying the authenticity of remote communication endpoints.\nThis vulnerability allows an unauthenticated, remote attacker to perform a protection mechanism bypass, potentially facilitating man-in-the-middle (MITM) attacks.\nAffected software includes Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nThe risk is critical as it undermines the integrity and confidentiality of data transmitted between the appliance and external services.\nExploitation does not require authentication and can be performed by an attacker with network access to the target, allowing the interception or manipulation of secure traffic flows.",
"technicalDetails": "The vulnerability originates from the failure of the Dell SCG application to correctly validate SSL/TLS certificates provided by remote servers during communication handshakes.\nBy neglecting to enforce strict certificate chain validation, including verifying the Certificate Authority (CA) signatures, expiration dates, or hostname mismatches, the application inadvertently accepts fraudulent or malicious certificates.\nThe exploitation flow begins when an attacker positions themselves as a man-in-the-middle between the Dell SCG instance and its intended destination. As the SCG appliance initiates an outbound connection, the attacker intercepts the request and presents a spoofed certificate to the SCG appliance.\nBecause the application logic does not perform a rigorous cryptographic verification of the presented certificate against a trusted trust store, it fails to identify the impersonation. Consequently, the SCG appliance establishes an encrypted tunnel directly to the attacker's infrastructure, believing it is communicating with a legitimate, trusted entity.\nOnce the session is established, the attacker can decrypt, inspect, and potentially modify the traffic in transit, effectively bypassing the security controls designed to protect the gateway's administrative or diagnostic communications.\nThis behavior exposes sensitive information—such as credentials, telemetry, or diagnostic logs—to unauthorized disclosure and allows for the injection of malicious commands or data into the gateway environment.\nThe vulnerability exists within the network communication modules of the SCG Appliance (versions < 5.36.00.16) and SCG Application (versions < 5.36.00.00).\nPost-exploitation impact includes full loss of confidentiality and integrity for the affected communication channels, which may be leveraged as a vector for further compromise of the appliance ecosystem.\nNo authentication or elevated privileges are required to initiate this attack, provided the attacker can reach the appliance's network interface to intercept the outbound traffic."
}