Impact
Dell Secure Connect Gateway 5.0 appliances and applications prior to the stated versions contain a least privilege violation that permits a highly privileged attacker with local access to bypass enforced restrictions and obtain unauthorized access to protected resources. The vulnerability originates from inadequate enforcement of local access controls within the software, enabling privileged users to elevate their permissions beyond intended limits. While the official description does not enumerate further damage, the possibility of unauthorized access undermines confidentiality and could facilitate additional exploitation if other weaknesses exist.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00 are affected. The vulnerability applies to the appliance and application components under the Dell:Secure Connect Gateway 5.0 product line.
Risk and Exploitability
The CVSS score of 3.4 indicates a low to moderate severity, and the EPSS score is unavailable, implying limited insight into current exploitation rates. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. An attacker would need local high privileges to exploit the flaw, which implies that attackers with physical or administrative access to the device could potentially pivot to unauthorized configuration changes or read sensitive settings. Given the local attack requirement and the relatively low severity rating, the risk is moderate but should be addressed promptly to prevent privilege escalation that could lead to broader compromise.
OpenCVE Enrichment