Impact
A vulnerability in Dell Secure Connect Gateway 5.0 Appliance and Application versions before 5.36.00.16/5.36.00.00 arises from improper handling of highly compressed data, allowing data amplification. An unauthenticated attacker who can reach the device over the network can trigger the flaw, causing the system to consume excessive resources and become unavailable. This flaw corresponds to the CWE‑409 weakness of improper resource management.
Affected Systems
Affected are Dell Secure Connect Gateway 5.0 Appliance and Application deployments. Specifically, any installation using Appliance version earlier than 5.36.00.16 or Application earlier than 5.36.00.00. The vulnerability is present in all device firmware and application containers that expose the vulnerable data processing routines to external traffic.
Risk and Exploitability
The flaw carries a CVSS score of 7.3, indicating a high severity. Since no EPSS data is published, current exploit probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The attack can be achieved remotely without authentication, making the risk practical for attackers who obtain network connectivity to the gateway. Mitigation relies on applying the Dell retainer update that resolves the data amplification issue. In the absence of a patch, administrators should consider blocking or limiting highly compressed traffic to reduce the likelihood of a denial‑of‑service event.
OpenCVE Enrichment