Impact
The vulnerability is an insufficient verification of data authenticity, allowing an attacker to capture a legitimate request and replay it repeatedly to obtain administrative access tokens. Because no nonce or time limit is enforced, the attack can be carried out indefinitely. This flaw, classified as CWE-345, could lead to full control over the Secure Connect Gateway appliance or application through unauthorized admin privileges.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Application versions before 5.36.00.00 are impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, yet the EPSS score is not available, so the probability of exploitation is unclear. The vulnerability is not listed in CISA KEV. Based on the description, the attack vector is remote over the network; an unauthenticated attacker can replay captured requests without any additional credentials. This scenario poses a significant risk to confidentiality and integrity of the system.
OpenCVE Enrichment