Impact
Dell Secure Connect Gateway 5.0 Appliance and Application versions before 5.36.00.16 and 5.36.00.00 respectively expose an Improper Limitation of a Pathname to a Restricted Directory vulnerability (Path Traversal). The flaw enables an unauthenticated attacker acting over a remote connection to read or write arbitrary files by manipulating path names. If successful, the attacker could inject malicious code or gain control of the system, thereby compromising confidentiality, integrity, and availability of the gateway services.
Affected Systems
The vulnerability is present in Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and in the Dell Secure Connect Gateway 5.0 Application before 5.36.00.00. Only these versions are impacted; newer releases are not affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the possibility of remote code execution qualifies it as a serious risk. An attacker does not need authentication, so the likelihood of successful exploitation in a connected environment is high. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog; however, the remote nature and potential for arbitrary code execution warrant prompt action. Based on the description, the attack vector involves remote network access to the gateway, likely via exposed management interfaces or services.
OpenCVE Enrichment