Impact
Dell Secure Connect Gateway 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 suffer from an improper certificate validation flaw (CWE-295). An attacker who can reach the device remotely does not need to authenticate first; by presenting a forged or trusted certificate chain during the TLS handshake, the attacker can bypass authentication controls and gain unauthorized access to the protected management interfaces or data. The vulnerability does not provide arbitrary code execution or elevate privileges beyond what the unauthenticated access already allows, which is why the CVSS score is modest at 3.7.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Only those product variants and versions are vulnerable; newer releases contain the fix.
Risk and Exploitability
The score of 3.7 reflects a low overall impact, and the exploitable attack vector is remote unauthenticated. While no EPSS data is available to gauge exploitation likelihood, the flaw resides in a critical security component and could be leveraged by a motivated attacker to obtain unauthorized access. The vulnerability is not currently listed in the CISA KEV catalog, indicating no publicly known widespread exploitation, but the risk to any organization that keeps older versions in production remains due to the potential for unauthorized data access.
OpenCVE Enrichment