Impact
This vulnerability is a Missing Authorization flaw that allows an unauthenticated attacker with remote access to send a specially crafted request to the Dell Secure Connect Gateway application, bypassing intended restrictions. Exploitation results in the execution of arbitrary commands on the target system, potentially jeopardizing the confidentiality, integrity, and availability of the network devices.
Affected Systems
Affected products are Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00. Any deployment of these older versions is susceptible to the described attack.
Risk and Exploitability
The CVSS score of 9.4 marks this issue as critical. The EPSS score is 1%, and it is not listed in the CISA KEV catalog, indicating that there is no confirmed active exploit yet. The likely attack vector is remote network access, as the vulnerability is exploitable by an unauthenticated attacker who can reach the gateway’s interface. Based on the description, the attack requires only the ability to send a crafted request to the application; no local privileges or privileged credentials are needed.
OpenCVE Enrichment