Impact
An unauthenticated attacker with remote access can control file names or paths on Dell Secure Connect Gateway 5.0, enabling the reading or writing of arbitrary files on the host. This elevation can reveal sensitive configuration data or allow malicious modifications, compromising system confidentiality and integrity. The flaw reflects CWE-73, an external control of file name or path weakness.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance models older than version 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application models older than version 5.36.00.00 are impacted. Only the appliance and application components of the SCG 5.0 series are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.3 indicates a high‑severity flaw, and although EPSS information is not available, the lack of a KEV listing suggests that widespread exploitation has not yet been observed. The likely attack vector is remote and unauthenticated, meaning that an attacker could exploit the weakness over any network connection that reaches the gateway’s management interface, potentially resulting in filesystem access if successful.
OpenCVE Enrichment