Impact
Dell Secure Connect Gateway 5.0 is impacted by an improper certificate validation flaw (CWE‑295). The vulnerability permits an attacker who can reach the gateway over the network to bypass the certificate checks that normally enforce authentication, allowing unauthorized access to the appliance or application and potentially compromising confidentiality, integrity, or availability of the data and services handled by the gateway.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The flaw exists in both the appliance and application components and can be triggered via any remote interface exposed to the network.
Risk and Exploitability
The flaw carries a CVSS score of 7.6, indicating high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. The attack vector is inferred to be network‑based remote access, as the description notes an unauthenticated attacker with remote access could potentially exploit the flaw. Immediate remediation is recommended.
OpenCVE Enrichment