Impact
The vulnerability arises from the use of hard‑coded cryptographic keys in Dell Secure Connect Gateway 5.0. This weakness is categorized as CWE‑321 and allows a low‑privileged attacker with remote access to bypass protection mechanisms, potentially enabling unauthorized actions or data access.
Affected Systems
Affected are Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. These versions do not include the key‑management updates required to eliminate hard‑coded keys.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate risk. EPSS is not available, and the lack of listing in CISA KEV suggests no public exploit has been documented yet. Attackers would need remote reach to the gateway and could leverage the weak key to circumvent authentication or other protection mechanisms. The risk is moderate but non‑negligible, especially in environments with low‑privileged users having network access to the appliance.
OpenCVE Enrichment