Impact
The vulnerability is an improper certificate validation flaw in Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.xx. It permits an attacker to bypass the gateway’s protection mechanisms by forging or accepting invalid certificates, potentially enabling unauthorized network access or traffic manipulation. The weakness arises from the application’s failure to enforce strict certificate checks during TLS handshakes.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance and Application are impacted. All builds of version 5.0 below 5.36.00.xx are vulnerable, typically deployed on Dell secure gateway appliances that expose remote management interfaces for connectivity. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and no EPSS score is available, suggesting limited evidence of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector involves remote access through exposed management or communication channels, allowing an unauthenticated attacker to bypass security checks. While the exploit does not compromise local credentials, it undermines gateway confinement and could facilitate further lateral movement within the protected network.
OpenCVE Enrichment