Impact
The vulnerability is a use of a hard‑coded cryptographic key in Dell Secure Connect Gateway 5.0 Appliance and Application. A low privileged attacker with local access can read or abuse this key, potentially exposing confidential data stored or transmitted by the gateway. The impact is the disclosure of sensitive information, as the attacker can reconstruct or decrypt data that should remain protected. No remote execution or privilege escalation is described, but the confidentiality loss may compromise broader network assets if the gateway is part of key infrastructure.
Affected Systems
Dell Secure Connect Gateway Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway Application versions older than 5.36.00.00 are affected. Only the specified appliance and application product lines are impacted; other Dell Secure Connect Gateway deployments with newer versions are not affected according to the CNA data.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium risk level. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation at present. The attack requires local, low‑privileged access, so the likelihood of exploitation depends on the local security posture. Because the weakness involves a hard‑coded key (CWE‑321), if an attacker gains local access they could use the key to decrypt traffic or other protected data, leading to potential downstream compromise if other assets rely on that key.
OpenCVE Enrichment