Impact
An Improper Authentication flaw in Dell Secure Connect Gateway 5.0 allows a remote attacker with low privileges to bypass protection mechanisms, potentially enabling unauthorized access to the appliance or application. The weakness is categorized as CWE‑287 and could compromise confidentiality, integrity, or availability if exploited. The description indicates that the attacker does not need privileged credentials but can leverage remote reachability to undermine the system’s authentication safeguards.
Affected Systems
This vulnerability affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. The affected products are the Appliance and Application components of the Secure Connect Gateway suite.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity. EPSS data is unavailable, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access by an attacker with low privileged credentials, which could lead to protection mechanism bypass if the vulnerability is successfully leveraged. The overall risk is moderate, but the absence of a KEV listing or EPSS score does not negate the need for timely remediation.
OpenCVE Enrichment