Impact
A relative path traversal flaw exists in Dell Secure Connect Gateway 5.0 Appliance and Application. The weakness allows a low‑privilege attacker who can reach the device over the network to request an arbitrary file path, potentially culminating in remote execution of arbitrary code. The vulnerability is classified as CWE‑23 and carries a CVSS score of 7.1, indicating a high‑severity risk when exploited. The description explicitly links this traversal flaw to remote code execution, implying a complete loss of confidentiality, integrity, and availability for affected systems.
Affected Systems
The flaw affects Dell Secure Connect Gateway Appliances running any version earlier than 5.36.00.16 and Applications earlier than 5.36.00.00. Systems identified as Dell:Secure Connect Gateway 5.0 – Appliance and Dell:Secure Connect Gateway 5.0 – Application are therefore exposed until patched to the specified or later releases.
Risk and Exploitability
With the CVSS score of 7.1, the vulnerability presents a serious threat. No EPSS score is available, but the lack of a KEV listing does not reduce the potential impact; discovery and exploitation remain likely in environments where the gateway is reachable from the Internet or untrusted networks. A low‑privileged attacker can trigger the traversal by crafting a request that includes malicious path components, and the system will resolve it, leading to remote code execution. Effective mitigation requires applying the vendor’s update as soon as possible.
OpenCVE Enrichment