---
id: CVE-2026-78489
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Certificate
  Validation vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Certificate
  Validation vulnerability. An unauthenticated attacker with remote access could
  potentially ex…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-295
vendor: dell
product: secure_connect_gateway
affected:
  - secure_connect_gateway < 5.36.00.00
  - secure_connect_gateway < 5.36.00.16
patched:
  - secure_connect_gateway 5.36.00.16
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T19:51:02.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78489'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T15:49:40.973774Z'
ingestedAt: '2026-09-14T13:53:06.856Z'
epss: 0.00132
epssPercentile: 0.03122
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

## Affected

- `secure_connect_gateway < 5.36.00.00`
- `secure_connect_gateway < 5.36.00.16`

## Remediation

Upgrade past the affected range:

- `secure_connect_gateway 5.36.00.16`
