Impact
The vulnerability is a Use of Incorrect Operator flaw that allows an attacker who can reach the system remotely to bypass authentication controls and gain unauthorized access. This could lead to the attacker obtaining privileged data or taking control of the device. The weakness aligns with CWE‑480, an improper authorization issue.
Affected Systems
Dell Secure Connect Gateway version 5.0 Appliances prior to 5.36.00.16 and Application components prior to 5.36.00.00 are affected. All deployments of these products that have not applied a later firmware or software update are at risk.
Risk and Exploitability
The CVSS base score of 7.3 indicates a medium to high severity. No EPSS value is available, so the likelihood of exploitation is undetermined, but the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is inferred to be remote because the description states an unauthenticated attacker with remote access could exploit the flaw.
OpenCVE Enrichment