Impact
The vulnerability is an Improper Certificate Validation flaw in Dell Secure Connect Gateway 5.0 that allows an attacker without prior authentication, but with remote network access, to potentially subvert the SSL/TLS handshake. By accepting a forged or invalid certificate, the attacker may gain unauthorized access to encrypted traffic, compromising the confidentiality and integrity of the data communicated through the gateway.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. No other vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 3.7 indicates a low‑to‑moderate severity. EPSS data is unavailable, and the vulnerability is not included in CISA’s KEV list. The exploit requires remote network access but no authentication, suggesting a network‑based attack path. While the low CVSS score reflects limited impact compared to other flaws, the ability to bypass certificate validation still enables an attacker to intercept or modify traffic, making the risk non‑negligible. Organizations should consider the potential for advanced persistent threats or targeted attacks when evaluating the threat.
OpenCVE Enrichment