Impact
The vulnerability is an insufficient entropy issue in the pseudorandom number generator, allowing a local attacker with low privileges to increase their privileges.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance, versions prior to 5.36.00.16, and Dell Secure Connect Gateway 5.0 Application, versions prior to 5.36.00.00, are affected.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate risk. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog. Based on the description, a local user or process with limited privileges may exploit the low-entropy PRNG to elevate privileges. Attackers would need local access and can achieve a higher level of control on the affected appliance or application.
OpenCVE Enrichment