Impact
Dell Secure Connect Gateway 5.0 Appliance and Application contain an improper certificate validation flaw that allows an unauthenticated attacker with remote access to present a forged or altered certificate that is accepted by the system. By doing so, the attacker can bypass the trust checks that underpin the gateway’s protection mechanisms, potentially allowing unauthorized connections or data manipulation.
Affected Systems
All Dell Secure Connect Gateway 5.0 Appliance releases older than 5.36.00.16 and all Application releases older than 5.36.00.00 are affected. The vulnerability exists in both the appliance and the application layers of the product.
Risk and Exploitability
The issue carries a CVSS score of 7.3, indicating high severity, and no EPSS score is published. It is not listed in the CISA KEV catalog. An attacker requires no credentials but remote access to the device’s management interface, making the exploit path straightforward and potentially impactful for systems exposed to external networks.
OpenCVE Enrichment