Impact
The vulnerability arises from an improper verification of cryptographic signatures in Dell Secure Connect Gateway 5.0. An attacker who can reach the gateway without authentication can trick the system into accepting a forged signature, thereby bypassing the built‑in protection mechanisms. This allows an attacker to potentially gain unauthorized access or elevate privileges within the infrastructure.
Affected Systems
Vendor Dell is affected for both the 5.0 Appliance and the 5.0 Application. Versions of the Appliance earlier than 5.36.00.16 and versions of the Application earlier than 5.36.00.00 are vulnerable. No other Dell products are specified as impacted.
Risk and Exploitability
The CVSS score of 5.6 suggests moderate severity. EPSS is not available, so the likelihood of exploitation is uncertain. Dell does not list this vulnerability in its KEV catalog. The attack would likely be initiated remotely by an unauthenticated attacker and relies on the gateway's failure to validate digital signatures properly. Because the compromise is a bypass of protection mechanisms, an attacker could achieve unauthorized actions that could lead to further compromise if additional controls are not in place.
OpenCVE Enrichment