Impact
The vulnerability in Dell Secure Connect Gateway 5.0 allows an attacker to exercise external control over critical state data. The flaw is identified as CWE-625 and can be exploited by an unauthenticated adversary who gains remote access, potentially resulting in unauthorized access to the system or its configuration.
Affected Systems
Affected are Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00; these versions are susceptible to the exploitation of the vulnerability.
Risk and Exploitability
The CVSS score is 5.3 indicating moderate risk. The EPSS score is not available, so the precise likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, unauthenticated access to the gateway, which can lead to the attacker gaining unauthorized control over critical configuration or state data.
OpenCVE Enrichment