Impact
Dell Secure Connect Gateway 5.0 Appliance and Application contain a use‑of‑hard‑coded‑cryptographic‑key flaw. The weakness allows an attacker to bypass intended cryptographic protection, enabling unauthorized read or modification of data protected by the appliance’s gateway functions. The vulnerability is classified as CWE‑321, indicating that the fixed key is insufficiently random and secret.
Affected Systems
The flaw affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Any installations running these earlier releases are vulnerable if not updated. The affected products are Dell Secure Connect Gateway appliances and their corresponding application components.
Risk and Exploitability
The CVSS score of 4.4 places the vulnerability in the moderate range, reflecting that remote exploitation is possible but requires an unauthenticated attacker to connect to the gateway services. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting that there is no documented active exploitation. Nonetheless, an attacker that successfully exploits the hard‑coded key could obtain unauthorized access to protected data or services.
OpenCVE Enrichment