Impact
An improper certificate validation flaw exists in Dell Secure Connect Gateway 5.0 for both the appliance and application components. The vulnerability allows an unauthenticated attacker with remote access to bypass certificate checks and gain unauthorized access to the system. The flaw is present in all releases prior to version 5.36.00.16 for the appliance and prior to 5.36.00.00 for the application.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00 are impacted. The issue affects the certificate validation mechanism used during remote connections, potentially exposing the gateway to attackers outside the local network.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity vulnerability, but because it can be exploited remotely by an unauthenticated attacker, it represents a risk of unauthorized access and possible compromise of network traffic. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the remote nature of the attack vector means that an adversary could exploit the flaw by simply initiating a connection to the gateway and presenting an untrusted certificate that is accepted due to the validation error.
OpenCVE Enrichment