Impact
An improper certificate validation flaw exists in Dell Secure Connect Gateway 5.0 Appliance and Application. An unauthenticated attacker with remote access can exploit the flaw, potentially allowing unauthorized connection establishment and access to the gateway. This weakness falls under CWE‑295, which centers on insufficient verification of digital certificates. The impact can include unauthorized data entry, control, or exfiltration if the attacker convinces the gateway to trust a malicious endpoint.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. The flaw is limited to the 5.0 appliance and application product lines and does not extend to newer major releases.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity. Because the EPSS score is not available, the current exploit probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote connection from an unauthenticated entity with network access to the gateway. No public exploitation is documented, but the CVSS baseline reflects the potential for significant risk.
OpenCVE Enrichment