Impact
The vulnerability is an unsynchronized access to shared data in a multithreaded context, classified as CWE-567. An attacker with low privileges who can reach the system remotely may trigger a resource exhaustion condition, leading to denial of service of the Dell Secure Connect Gateway service.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are vulnerable. These products are commonly deployed in virtualized data center environments to provide secure remote access.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. No EPSS score is available, so the probability of exploitation remains uncertain. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation reports. The likely attack vector is remote and requires low‑privilege access, with impact limited to service availability rather than confidentiality or privilege escalation.
OpenCVE Enrichment