Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical security vulnerability impacting Dell Secure Connect Gateway appliances and applications. The issue allows unauthenticated remote attackers to gain unauthorized administrative access by repeatedly reusing captured requests, potentially enabling sustained system compromise. Dell recommends immediate upgrades to mitigate this risk.
- Unauthenticated access granted via request replay.
- Confirms management gateway exposure risks.
- Prioritize assessment of this gateway vulnerability.
Attack Path
How an attacker could exploit the issue
An attacker could reach the Dell Secure Connect Gateway appliance or application with remote access. By reusing captured requests without checks, the attacker can gain administrative access and refresh tokens. This allows for ongoing unauthorized control of the system.
- Requires remote access, no authentication needed.
- Reusing captured requests triggers the vulnerability.
- Results in unauthorized administrative access.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker with network access to gain administrative control of the Dell SCG appliance by repeatedly reusing captured requests. This could lead to unauthorized access and manipulation of the appliance's functions.
- Administrative access to the appliance.
- Reusing captured network requests.
- Unauthorized system control.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for Dell Secure Connect Gateway appliances and applications should prioritize identifying all deployed instances. Confirming reachability and business criticality is essential to assess risk and identify the accountable owner for remediation planning.
- Application or Infrastructure owners
- Verify external reachability and business impact.
- Plan and execute vendor-provided updates.