Impact
Dell Secure Connect Gateway 5.0 contains an Improper Certificate Validation flaw that allows a remote, unauthenticated attacker to bypass certificate checks and gain unauthorized access to the appliance or application. This weakness (CWE‑295) can be used to impersonate trusted connections, potentially exposing sensitive management interfaces and network traffic.
Affected Systems
Versions of Dell Secure Connect Gateway Appliance 5.0 earlier than 5.36.00.16 and versions of Dell Secure Connect Gateway Application 5.0 earlier than 5.36.00.00 are vulnerable. The flaw exists in both the appliance and application components of the gateway.
Risk and Exploitability
The vulnerability has a CVSS score of 7.4, indicating a high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker with network access to the gateway can exploit the certificate validation weakness without prior authentication, leading to unauthorized control of the system.
OpenCVE Enrichment