Impact
An improper certificate validation flaw in Dell Secure Connect Gateway 5.0 Appliance and Application allows an unauthenticated attacker with remote access to bypass security checks, potentially gaining unauthorized access to system resources. Because the vulnerability directly undermines transmission integrity and authentication guarantees, it can expose sensitive configuration data, compromise network traffic, or provide a foothold for further attacks. The weakness arises from failure to verify digital certificates as required by standard TLS rules, thereby enabling man‑in‑the‑middle or spoofing attacks.
Affected Systems
The flaw affects all Dell Secure Connect Gateway 5.0 Appliance builds earlier than version 5.36.00.16 and all 5.0 Application builds earlier than 5.36.00.00. These products provide secure connectivity for enterprise networks and are typically deployed on‑premise or as virtual appliances, meaning that vulnerability exposure could impact a broad range of deployment scenarios.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. No EPSS metric is available, but the flaw is exploitable remotely without authentication, meaning attackers could potentially gain privileged access or disrupt connectivity. Although not yet listed in CISA's KEV catalog, the lack of current public exploits does not diminish the criticality of addressing the vulnerability promptly.
OpenCVE Enrichment