Impact
The vulnerability is a download of code without integrity check that allows an unauthenticated attacker with remote access to execute arbitrary commands on Dell Secure Connect Gateway 5.0 devices. The flaw is classified as CWE-494 and can result in full system compromise if exploited successfully.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. These products must be identified and updated accordingly.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. EPSS is not available, so the exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated remote connection, such as via the public network interfaces exposed by the appliance or application. If an attacker can reach the vulnerable endpoint, the absence of an integrity check allows malicious code to be downloaded and executed, giving the attacker full control over the affected system.
OpenCVE Enrichment