Impact
An improper certificate validation flaw exists in Dell Secure Connect Gateway 5.0 Appliance and Application. The flaw allows an unauthenticated attacker with remote access to bypass the gateway's protection mechanisms by presenting a forged certificate. Consequently, the attacker could gain unauthorized control or compromise the integrity of the gateway without authenticating.
Affected Systems
Vulnerable devices include Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Systems running any of these older releases are at risk.
Risk and Exploitability
The CVSS base score of 5.9 indicates a medium severity. EPSS score is not available, so the current exploitation probability is unclear, and the vulnerability is not listed in KEV. The likely attack path involves an unauthenticated attacker remotely connecting to the gateway and tricking it into accepting a malicious certificate, thereby bypassing authentication. Given the moderate score, monitoring and timely patching are prudent to reduce risk.
OpenCVE Enrichment