Impact
The vulnerability is a use of hard‑coded credentials in Dell Secure Connect Gateway 5.0, allowing an unauthenticated attacker with remote access to obtain unauthorized access. This flaw can potentially grant administrative privileges to the attacker, leading to full control of the device and any networks it connects to. The flaw is present in appliances prior to version 5.36.00.16 and applications prior to 5.36.00.00.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance models running a version older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application models running a version older than 5.36.00.00 are affected. Only these product lines are vulnerable to the hard‑coded credential issue.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. Although the EPSS score is not provided, the lack of a listed KEV status means no known public exploits have been documented yet. Nonetheless, the vulnerability allows unauthenticated remote attackers to potentially compromise the appliance or application, making this a critical concern for systems exposed to external networks. An attacker could exploit the flaw by connecting remotely and using the default credentials, leading to unauthorized control of the gateway.
OpenCVE Enrichment