Impact
Server‑Side Request Forgery (SSRF) in Dell Secure Connect Gateway 5.0 Appliance and Application allows an unauthenticated attacker with remote access to trigger internal requests through the gateway, potentially exposing internal resources or enabling further lateral movement. The flaw stems from insufficient validation of outbound requests, categorized as CWE‑918. The attacker could retrieve sensitive internal data or interact with services that are otherwise only reachable within the internal network.
Affected Systems
Vulnerable versions are all Dell Secure Connect Gateway 5.0 Appliances older than 5.36.00.16 and all Application releases older than 5.36.00.00. These affect the Dell Secure Connect Gateway 5.0 Appliance and Dell Secure Connect Gateway 5.0 Application components deployed by organizations using Dell's secure connectivity platform.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability with a medium to high exploitation potential. Because the attack requires only unauthenticated remote access, an attacker could exploit it from outside the protected network without compromising credentials. The EPSS score is unavailable, so the current exploitation probability cannot be precisely quantified, and the vulnerability is not yet listed in the CISA KEV catalog. Administrators should treat it as a serious risk pending patch availability.
OpenCVE Enrichment