Impact
Improper certificate validation in Dell Secure Connect Gateway 5.0 Appliance and Application allows an unauthenticated attacker with remote access to bypass TLS certificate checks, potentially gaining unauthorized control over the device. The vulnerability can lead to compromise of confidentiality and integrity by enabling a man‑in‑the‑middle or spoofing attack.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. Systems running these releases should update to the recommended versions.
Risk and Exploitability
The CVSS base score of 7.7 indicates a high severity risk. EPSS is not available and the vulnerability is not listed in CISA KEV, but the lack of certificate validation means a remote, unauthenticated attacker can exploit it without needing credentials. The exploit requires only network connectivity to the appliance and involves presenting a forged certificate to the gateway, making it a significant risk for exposed environments.
OpenCVE Enrichment