CVE-2026-80164
7.4Dell · Secure Connect Gateway
Dell Secure Connect Gateway contains an improper certificate validation vulnerability that allows remote, unauthenticated attackers to potentially gain unauthorized access to the affected system.
Executive summary
A high-severity improper certificate validation vulnerability in Dell Secure Connect Gateway could allow remote, unauthenticated attackers to gain unauthorized access to the appliance.
Vulnerability
This vulnerability involves improper certificate validation (CWE-295), which allows an unauthenticated remote attacker to bypass identity verification and achieve unauthorized access to the application or appliance.
Business impact
Successful exploitation of this vulnerability could lead to a significant compromise of system integrity and confidentiality, as unauthorized parties may intercept or manipulate sensitive communications. Given the CVSS score of 7.4, this issue presents a high risk to organizational security, potentially resulting in data exfiltration or the unauthorized control of administrative gateway functions.
Remediation
Immediate Action: Administrators must update Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later, and the Application version to 5.36.00.00 or later, as specified in the Dell security advisory.
Proactive Monitoring: Security teams should monitor network traffic and system access logs for anomalous authentication attempts or unusual connection patterns originating from external sources.
Compensating Controls: Deploying a Web Application Firewall (WAF) or restricting network access to the gateway interface to trusted IP addresses can help mitigate the risk while the update is being scheduled.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the high severity of this vulnerability and the potential for unauthenticated remote access, immediate remediation is required. Organizations should prioritize patching their Dell Secure Connect Gateway instances to the specified versions to eliminate the risk of unauthorized exploitation.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section