Impact
This vulnerability is a Missing Authentication for a critical function that allows an unauthenticated attacker with remote access to gain unauthorized control. Because authentication is not required, an attacker could trigger privileged actions within the appliance or application, potentially altering configuration, accessing sensitive data, or enabling further compromise. The impact is mainly to confidentiality and integrity, as the attacker can read or modify protected resources without any credential check.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and while the EPSS score is not available, the lack of the vulnerability in the KEV catalog suggests it has not yet seen widespread exploitation. The likely attack vector is remote; an attacker only needs network connectivity to the appliance or application and no authentication. If successful, the attacker can obtain unauthorized access to critical functions.
OpenCVE Enrichment