Impact
Dell Secure Connect Gateway 5.0 Appliance and Application prior to specific releases contain a certificate validation flaw that permits an attacker who can reach the system remotely without authentication to bypass normal certificate checks and gain unauthorized access. The vulnerability is directly tied to the weaknesses identified as CWE‑295, where the software does not properly validate certificates presented during secure communications. The resulting unauthorized access could undermine the confidentiality and integrity of the secure connections that the appliance and application provide, allowing an attacker to potentially impersonate a trusted partner or manipulate data in transit.
Affected Systems
The affected systems are Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. The vulnerability applies to all deployments of these early releases, regardless of deployment environment, as the flawed certificate validation logic is embedded in the core gateway software.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate severity, and no EPSS data is available, so the exploitation probability is unknown. The vulnerability is listed as not in the CISA KEV catalog, suggesting no known publicly available exploits. Based on the description, an unauthenticated attacker who can reach the gateway remotely could exploit the flaw, achieving unauthorized access to clear or tamper with secure tunnels set up by the gateway.
OpenCVE Enrichment