Impact
Dell Secure Connect Gateway 5.0 includes a race condition bug that enables concurrent execution using a shared resource without proper synchronization. The flaw allows an unauthenticated attacker with remote access to trigger a denial of service by exhausting or corrupting shared state. The weakness is classified as a concurrent execution race condition (CWE-567).
Affected Systems
Versions of the Dell Secure Connect Gateway 5.0 Appliance before 5.36.00.16 and versions of the Dell Secure Connect Gateway 5.0 Application before 5.36.00.00 are vulnerable. The vulnerability applies to both the appliance and the application components of the product suite.
Risk and Exploitability
The vulnerability is scored with a moderate CVSS score of 5.3. EPSS is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote, unauthenticated, and can be exercised by an external actor. Exploitation would cause service interruption for legitimate users but does not appear to provide confidentiality or integrity compromise.
OpenCVE Enrichment