Impact
The vulnerability is an Improper Validation of Certificate with Host Mismatch flaw (CWE-297). An unauthenticated attacker with remote access could deliberately present a certificate that, while matching the expected host name, fails the gateway’s validation rules, allowing the attacker to bypass the secure connection verification intended to guard against unauthorized connections.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are susceptible to this flaw; these product lines are impacted by the identified certificate validation weakness.
Risk and Exploitability
With a CVSS score of 4.8, the severity of this issue is moderate, and no EPSS score is provided so the probability of exploitation remains unknown. The vulnerability is not listed in the CISA KEV catalog, reducing immediate visibility. Attack requires unauthenticated remote access to the gateway over a network channel, meaning vulnerable installations exposed to external networks face a non‑negligible risk of bypassing the gateway’s protection mechanism.
OpenCVE Enrichment