Impact
The vulnerability is an OS command injection flaw that allows a low privileged attacker with local access to execute arbitrary operating system commands. The flaw arises from improper handling of special characters, enabling the attacker to inject commands into the system shell. Successful exploitation would compromise the confidentiality, integrity, or availability of the affected system depending on the commands run.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. The product names are Dell Secure Connect Gateway 5.0 Appliance and Dell Secure Connect Gateway 5.0 Application.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. A local attacker with low privileges can exploit the flaw, but remote exploitation is not indicated. The risk is limited to systems where local access is possible and the attacker can reach the vulnerable code.
OpenCVE Enrichment