Impact
The vulnerability is an execution with unnecessary privileges that allows a highly privileged attacker to elevate their privileges and gain unauthorized access to the system. This flaw does not directly expose remote code execution or denial of service, but it permits local attackers to bypass intended security boundaries and access sensitive data or services. The weakness is identified as CWE-250, where an application incorrectly allows users to perform privileged actions better than intended.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance and Application earlier than version 5.36.00.16 for the appliance and earlier than 5.36.00.00 for the application are affected. These appliances are used to provide secure connectivity for enterprise networks and rely on local administrative privileges for configuration and maintenance.
Risk and Exploitability
The CVSS score of 3.4 indicates low overall impact, but the absence of an EPSS score means exploitation likelihood is unknown. The flaw is not listed in the CISA KEV catalog, suggesting no publicly disclosed exploits. The attack requires high local privileges, therefore a local attacker with such access can exploit it. Once exploited, the attacker gains unauthorized access to resources beyond their intended scope.
OpenCVE Enrichment