Impact
The vulnerability is an improper certificate validation flaw in Dell Secure Connect Gateway 5.0 Appliance and Application. A low‑privileged attacker with local access can bypass TLS server‑certificate checks, allowing the gateway to send arbitrary requests to internal services and thereby perform server‑side request forgery. This flaw is classified as CWE‑295.
Affected Systems
Affected are Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. These versions are found in virtual or appliance deployments used for secure remote access.
Risk and Exploitability
The CVSS assessment rates this vulnerability as 5.5, indicating moderate severity. No EPSS score is publicly available, and the flaw is not listed in the CISA KEV catalog. The exploit requires local, low‑privileged access; the attacker leverages the certificate‑validation bypass to forge internal requests. While remote exploitation is not feasible, organizations permitting local account usage without strict controls are at risk.
OpenCVE Enrichment