Impact
An OS Command Injection flaw exists in Dell Secure Connect Gateway 5.0 versions prior to 5.36.00.00. The vulnerability results from improper neutralization of special elements used in an operating‑system command. It allows an unauthenticated attacker with remote access to supply crafted input that is passed to the underlying shell, enabling execution of arbitrary system commands. This could lead to compromise of the gateway service, potentially affecting the confidentiality and integrity of network traffic passing through the appliance.
Affected Systems
All Dell Secure Connect Gateway 5.0 (Application) and Dell Secure Connect Gateway 5.0 – Appliance deployments that are running a version earlier than 5.36.00.00 are affected. The issue does not apply to newer releases, including 5.36.00.00 and later.
Risk and Exploitability
The CVSS score of 7.3 reflects high impact potential. The EPSS score of 1 % indicates a low, but non‑zero, probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access to the SCG appliance; an attacker can trigger the flaw through unsanitized input sent over exposed interfaces. Successful exploitation would allow the attacker to execute arbitrary OS commands on the appliance.
OpenCVE Enrichment