Impact
An improper limitation of pathname to a restricted directory in Dell Secure Connect Gateway 5.0 allows an unauthenticated remote attacker to perform path traversal, potentially accessing or modifying files outside the intended directory structure. This can lead to unauthorized read or write operations, giving the attacker control over critical configuration files or other sensitive data.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The vulnerability is present in both the appliance and the application components of the Secure Connect Gateway platform released by Dell.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high risk level. Although the EPSS score is not reported, the lack of a KEV listing does not diminish the potential for exploitation via unauthenticated remote access. An attacker can exploit this path traversal flaw without credentials, making it easier to gain unauthorized access to the gateway's file system if the device is exposed to an untrusted network.
OpenCVE Enrichment