Impact
The vulnerability is an Improper Privilege Management flaw that allows an unauthenticated attacker with local access to elevate privileges on Dell Secure Connect Gateway 5.0 Appliance and Application. This flaw is classified as CWE-269 and can enable the attacker to gain administrative or higher rights, leading to potential system compromise or additional attacks. The impact is local privilege escalation which, if combined with other vulnerabilities, may permit full control over the device.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are impacted. The vulnerable software is provided as an appliance or application bundle from Dell and is commonly deployed in corporate VPN or remote access environments.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8 indicating high severity. No EPSS data is available and it is not listed in the CISA KEV catalog, suggesting no known public exploitation has been observed. The likely attack vector requires local, unauthenticated access, meaning the attacker must have local network presence to the device for exploitation. While this limits exposure to environments where local access is possible, the high severity and privilege escalation potential warrant prompt remediation.
OpenCVE Enrichment