Impact
A relative path traversal flaw exists in Dell Secure Connect Gateway 5.0 Appliance and Application. An unauthenticated attacker who can reach the device remotely could cause a path traversal that allows reading of arbitrary files on the device's filesystem. The weakness, classified as CWE-23, undermines file system isolation and may expose configuration data, credentials, or other sensitive information.
Affected Systems
Affected versions are Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. Both product lines are deployed in organizations that use Dell's secure connectivity platform.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is "remote unauthenticated access" to the gateway. Exploitation would require the attacker to send a specially crafted request that triggers the path traversal during file retrieval or configuration access. No public exploit code has been reported at this time, but the potential for remote unauthorized file disclosure remains if the gateway remains reachable from an untrusted network.
OpenCVE Enrichment