Impact
An unnamed vulnerability has been identified in Dell Secure Connect Gateway 5.0 that allows an attacker to bypass protection mechanisms by exploiting improper certificate validation. The flaw permits an unauthenticated entity with remote access to supply a forged or otherwise invalid certificate and have it accepted, potentially allowing the attacker to establish a connection that is otherwise restricted. This could lead to confidentiality or integrity compromise of communication channels or services that rely on the gateway for secure access.
Affected Systems
The issue affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Systems running these specific older releases are vulnerable, while newer versions released after those dates contain the fix.
Risk and Exploitability
The CVSS score of 5.6 indicates a medium severity level. Exploitation can be achieved by an unauthenticated attacker with remote access, and no password or privileged credentials are required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it has not yet been widely exploited in the wild. Nonetheless, the remote nature of the attack and the absence of authentication make it a realistic risk for exposed gateway deployments.
OpenCVE Enrichment