PatchSiren cyber security CVE debrief
CVE-2026-79975 Dell CVE debrief
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 contain an Improper Certificate Validation vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to server-side request forgery. This vulnerability exists in the certificate validation process of Dell SCG 5.0 Appliance and Application, which could allow an attacker to manipulate server requests. Defenders should assess exposure and prioritize verification of local access controls.
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for Dell SCG 5.0 Appliance and Application systems, particularly those with local access controls, should assess exposure and prioritize verification. This includes operators, platform administrators, vulnerability management teams, and security teams who manage or secure Dell SCG 5.0 Appliance and Application systems.
Why it matters
Defenders should prioritize verifying exposure and assessing local access controls for Dell SCG 5.0 Appliance and Application systems, as a low-privileged attacker could exploit this Improper Certificate Validation vulnerability, potentially leading to server-side request forgery. Evidence is limited, and additional information on affected systems and exploitation is required for comprehensive remediation.
- Verification of local access controls and user privileges is necessary to prevent potential exploitation.
- Assessment of exposure for Dell SCG 5.0 Appliance and Application systems is crucial to prioritize remediation.
Technical summary
The vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. A low-privileged attacker with local access could potentially exploit this Improper Certificate Validation vulnerability, leading to server-side request forgery. This vulnerability could allow an attacker to manipulate server requests by exploiting the certificate validation process in Dell SCG 5.0 Appliance and Application systems. Defenders should prioritize verifying exposure and assessing local access controls.
Defensive priority
Defenders should prioritize verifying exposure and assessing local access controls, as a low-privileged attacker could exploit this vulnerability.
Recommended defensive actions
- Verify local access controls and user privileges
- Assess exposure of Dell SCG 5.0 Appliance and Application systems
- Review and update certificate validation configurations
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected systems and exploitation is limited. Evidence is based on CVE Program and NVD sources, which may not cover all affected deployments or exploitation scenarios. Defenders should verify exposure and assess local access controls for Dell SCG 5.0 Appliance and Application systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.