Impact
This vulnerability reflects an improper certificate validation flaw in Dell Secure Connect Gateway 5.0. An attacker who can reach the device’s management interface from outside the network does not need existing credentials to exploit the weakness, allowing unauthorized authentication or session takeover once the certificate check is bypassed. The flaw jeopardizes the confidentiality and integrity of protected traffic handled by the gateway and enables potential lateral movement within the protected network.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are susceptible.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. EPSS information is currently unavailable, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack requires remote connectivity but not authentication, so any external host with network access to the gateway’s management interface may attempt exploitation. Inferred from the description that the vector is remote, and an unauthenticated user can trigger it.
OpenCVE Enrichment