Impact
Dell Secure Connect Gateway versions prior to the specified updates contain a flaw that allows an attacker to exploit improper validation of certificates. This weakness can lead to the bypass of security controls, potentially giving attackers unauthorized access or the ability to tamper with protected communications. The impact is focused on integrity and confidentiality of data exchanged through the gateway, as the attacker may impersonate trusted endpoints or evade authentication checks.
Affected Systems
The vulnerability affects Dell Secure Connect Gateway Appliance version 5.0 prior to 5.36.00.16 and Dell Secure Connect Gateway Application version 5.0 prior to 5.36.00.00. Systems running any earlier release of these components are potentially exposed.
Risk and Exploitability
The flaw is rated with a CVSS score of 5.9, indicating medium severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack vector is remote, with an attacker needing only network access to the gateway; authentication is not required. Exploitation would involve presenting a forged or manipulated certificate to the gateway to gain privileged actions or modify traffic, thereby bypassing built-in protection mechanisms.
OpenCVE Enrichment