Impact
This vulnerability arises from the use of hard‑coded cryptographic keys within Dell Secure Connect Gateway 5.0. The flaw, identified as CWE-321, permits a low‑privileged local attacker to access encrypted data, potentially exposing sensitive information. Although the vulnerability does not grant arbitrary code execution, the leaking of cryptographic material can compromise confidentiality when attackers are already able to run code locally.
Affected Systems
The flaw affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. These versions are part of the appliance and application deployments released by Dell.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. A local attacker with low privileges can exploit the hard‑coded key, leading to information disclosure. Exploitation requires local access, so presence of network privileges alone is insufficient.
OpenCVE Enrichment