Impact
The vulnerability is a Relative Path Traversal flaw that allows an unauthenticated attacker with remote access to construct file paths that reference system files. Exploitation can lead to arbitrary code execution on the affected system. This weakness aligns with CWE-23, a well-known weakness that can compromise confidentiality, integrity, and availability.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a medium to high severity. EPSS data is missing, so the current exploitation likelihood is unclear, but the lack of a KEV listing suggests no documented active exploitation yet. The likely attack vector is remote, unauthenticated access, meaning any host that can reach the gateway over the network could attempt the exploit.
OpenCVE Enrichment