Impact
An improper locking race condition in Dell Secure Connect Gateway 5.0 allows a low‑privileged attacker with remote access to bypass file‑system access controls, leading to read or write access to protected files. The vulnerability is identified as CWE‑667 and does not grant arbitrary code execution but enables the attacker to access sensitive configuration or user data. The impact is confined to confidentiality and integrity of the file system rather than system availability.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00 are affected. These appliances provide remote VPN and connectivity services and are typically deployed in perimeter or data‑center environments.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is a remote low‑privileged connection that can exploit the race condition to gain unauthorized filesystem access. The absence of a public exploit means the risk is mainly theoretical until a vulnerability is leveraged in the wild.
OpenCVE Enrichment