Impact
Dell Secure Connect Gateway 5.0 appliance and application contain a Time-of-check Time-of-use (TOCTOU) race condition that may be triggered without authentication by an attacker with remote access. When exploited, the race condition can cause the system to become unresponsive, resulting in a denial‑of‑service for legitimate users. The vulnerability is a classic concurrency flaw (CWE‑367) and does not directly expose data or allow code execution.
Affected Systems
The flaw affects Dell Secure Connect Gateway 5.0 appliance versions earlier than 5.36.00.16 and application versions earlier than 5.36.00.00. Users running any of these vulnerable releases are potentially exposed.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, largely due to the availability impact. EPSS is not available, so the current likelihood of exploitation is unclear. It is not listed in the US CISA KEV catalog, and no public exploits are known. The attack vector is inferred to be remote, unauthenticated access to the SCG components, which could allow an attacker to force a DoS without further privileges.
OpenCVE Enrichment