Impact
This vulnerability is an improper limitation of a pathname to a restricted directory (CWE-22). An unauthenticated attacker with remote access can traverse directories and execute code, potentially compromising the entire appliance. The flaw may allow the attacker to write to privileged locations and launch arbitrary processes.
Affected Systems
All Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and all Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00 are affected. These systems are reachable remotely and lack authentication checks for path traversal.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, while the EPSS score is not available, suggesting no known widespread exploitation yet. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker can exploit the flaw remotely without needing credentials, potentially leading to remote code execution through a path traversal attack.
OpenCVE Enrichment