Impact
The vulnerability is an Improper Certificate Validation flaw that can allow an unauthenticated attacker to bypass security checks and gain unauthorized access. This weakness can be exploited remotely and may compromise the confidentiality and integrity of the system, potentially granting an attacker full control over the affected device.
Affected Systems
Dell Secure Connect Gateway Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway Application versions older than 5.36.00.00 are vulnerable. The issue impacts the Dell SCG 5.0 appliance and application components.
Risk and Exploitability
The CVSS score is 7.4, indicating a high severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not currently listed in CISA KEV. An unauthenticated attacker could potentially exploit the flaw remotely, assuming network access to the SCG components. The main risk is unauthorized access, which could lead to broader compromise if the attacker can further traverse the network.
OpenCVE Enrichment