Impact
Dell’s Secure Connect Gateway 5.0 Appliance and Application have a critical missing‑authentication flaw that may allow an attacker who can reach the device over the network to gain unrestricted access to sensitive configuration and control functions. The flaw is described as a Missing Authentication for Critical Function; an unauthenticated attacker with remote access could potentially alter settings or elevate privileges, which compromises confidentiality, integrity, and availability of the gateway services. The weakness is classified as CWE‑306, a lack of authentication for operations that rely on authenticated sessions.
Affected Systems
Both the Dell Secure Connect Gateway 5.0 Appliance and the Application are impacted. In particular, versions prior to 5.36.00.16 on the Appliance and earlier than 5.36.00.00 on the Application contain the flaw. Administrators should check the version of their installation against these thresholds to determine if the device is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated adversary establishing a remote connection to the gateway’s management interface and then exploiting the missing authentication to perform critical functions. Because the flaw is not tied to a web‑interface specific injection, exploitation depends on network reachability and the absence of any authentication controls at the network layer.
OpenCVE Enrichment