Impact
This vulnerability permits an attacker to bypass TLS hostname verification by supplying a forged certificate that appears to match the expected identity, allowing the attacker to establish a trusted session with the gateway without authentication and gain unauthorized access to the device's management interface and potentially the connected network.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. Newer releases of these products incorporate the certificate validation fix.
Risk and Exploitability
The CVSS score of 7.0 reflects medium severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, so the exploitation likelihood is unknown at present. An unauthenticated attacker with remote network access can exploit the flaw by presenting a forged certificate during the TLS handshake, leveraging the lack of hostname validation to establish a privileged session.
OpenCVE Enrichment