Impact
Dell Secure Connect Gateway 5.0 applied hard‑coded cryptographic keys; a low privileged attacker with local access can exploit the flaw to read sensitive information. The vulnerability is an instance of improper key management that can lead to data leakage without remote access.
Affected Systems
Appliance versions below 5.36.00.16 and Application versions below 5.36.00.00 are affected. Dell Secure Connect Gateway users must verify their deployments against these thresholds.
Risk and Exploitability
The CVSS base score is 5.5, indicating moderate risk. No EPSS data is available and the vulnerability is not in the CISA KEV catalog. The attack vector requires local access and low privileges; an attacker who achieves local foothold could read protected data, but cannot compromise the system remotely or alter data.
OpenCVE Enrichment