Impact
Dell Secure Connect Gateway 5.0 exposes an Improper Authentication vulnerability that allows a low‑privileged attacker with remote access to bypass normal authentication controls. The flaw can lead to unauthorized access to management interfaces and potentially to the underlying appliance or application resources. The weakness is a classic authentication bypass, categorized as CWE‑287.
Affected Systems
The vulnerability affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Both the appliance and application components listed under Dell’s Secure Connect Gateway product line are susceptible.
Risk and Exploitability
The CVSS score of 6.4 places this flaw in the moderate severity range. No EPSS score is published, so the current exploitation probability is unknown, and it is not listed in the CISA KEV catalog. The attack vector is remote, requiring only low‑privilege or guest access to trigger the authentication failure. Because the flaw permits bypassing authentication, successful exploitation could provide an attacker with full control over configuration and potentially data exfiltration.
OpenCVE Enrichment