Impact
The vulnerability is an Improper Certificate Validation flaw that allows a remote attacker to bypass the security mechanisms of Dell Secure Connect Gateway 5.0. If exploited, the attacker can present a forged or otherwise non‑trusted certificate and gain privileged access or modify connections, thereby compromising confidentiality and integrity of the system. The weakness is identified as CWE‑295.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Users of these product lines should verify their current build against these baseline versions.
Risk and Exploitability
The CVSS score of 5.9 indicates medium severity. No EPSS score is available, and the issue is not listed in CISA KEV. Based on the description, the attack vector is inferred to be unauthenticated remote access; an attacker can trigger the flaw over the public interface without needing credentials. The risk is moderate with no evidence of widespread exploitation to date.
OpenCVE Enrichment