Impact
The vulnerability is a missing authentication flaw for a critical function in Dell Secure Connect Gateway 5.0. It allows an attacker to bypass authentication controls and gain unauthorized access, potentially compromising the integrity of the appliance or application. The weakness is identified as CWE-306.
Affected Systems
The flaw affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Any deployment running those versions is susceptible.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available, so the likelihood of exploitation is unknown, but the vulnerability is not listed in CISA’s KEV catalog. The description indicates the flaw can be reached over remote access, meaning the attack vector is inferred to be network-based and requires no local privileges.
OpenCVE Enrichment