Impact
Dell Secure Connect Gateway (SCG) 5.0 prior to 5.36.00.00 suffers from an OS Command Injection flaw where an attacker can supply unsanitized input that is passed to the operating system shell. The vulnerability allows unprivileged, unauthenticated remote users to execute arbitrary system commands, potentially compromising the entire gateway service.
Affected Systems
The issue affects Dell Secure Connect Gateway 5.0 Application and Dell Secure Connect Gateway 5.0 – Appliance for all releases earlier than 5.36.00.00.
Risk and Exploitability
The CVSS score of 7.3 indicates a high impact potential, and although an EPSS score is not available, the flaw is not listed in the CISA KEV catalog. Unauthenticated remote attackers can exploit this weakness, which could lead to complete takeover of the appliance if no network restrictions are in place.
OpenCVE Enrichment