Impact
The vulnerability resides in the use of a hard‑coded cryptographic key within Dell Secure Connect Gateway version 5.0, classified as CWE‑321. An attacker can potentially extract sensitive data that the gateway manages, resulting in a breach of confidentiality. The flaw does not permit direct modification or destruction of configuration, but it does create a vector for clandestine data disclosure.
Affected Systems
All Dell Secure Connect Gateway 5.0 Appliances running a version older than 5.36.00.16 and all 5.0 Application components older than 5.36.00.00 are susceptible. These are identified by Dell under the Secure Connect Gateway product line.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, and the EPSS score is unavailable. The vulnerability is not currently listed in CISA’s KEV catalog. An unauthenticated attacker with remote access can potentially acquire the hard‑coded key and use it to read protected information. The lack of authentication requirements means that the attack could be performed without special credentials, though it still requires network reachability to the gateway.
OpenCVE Enrichment