Impact
This flaw is a missing authentication vulnerability affecting critical functions in Dell Secure Connect Gateway 5.0. An unauthenticated attacker with remote access could potentially exploit the flaw to gain unauthorized access to the appliance or application, compromising control over the device. The vulnerability is rated with a CVSS score of 8.1.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity and the lack of an EPSS score means a precise exploitation probability is unknown. The vulnerability is not listed in CISA KEV. The attack vector is remote and requires no authentication, so any host with network connectivity to the appliance or application could be targeted. Organizations that run legacy deployments without the update are at risk of exposure.
OpenCVE Enrichment