Impact
Dell Secure Connect Gateway Policy Manager versions before 5.34.00.16 contain an Improper Certificate Validation flaw. This weakness allows an unauthenticated attacker with network access to trick the system into accepting a forged certificate, which can lead to denial of service, information disclosure, and potentially remote code execution. The described impact is consistent with CWE‑295, highlighting a failure in validating cryptographic certificates.
Affected Systems
Dell Secure Connect Gateway Policy Manager is the affected product. Vulnerable releases are all versions prior to 5.34.00.16. No further sub‑versions are listed. Users running affected builds should verify that they are deployed with the latest 5.34.00.16 or later release.
Risk and Exploitability
The CVSS score of 7.5 marks the issue as High severity, while the EPSS score is not available, indicating insufficient publicly documented exploit data. The vulnerability is not in the CISA KEV catalog, suggesting it has not been publicly exploited yet. An attacker would need remote connectivity to the management interface, with no authentication, to leverage the certificate issue. If successful, the attacker could disrupt services, extract sensitive information, or execute arbitrary commands on the SCG appliance.
OpenCVE Enrichment