Impact
This vulnerability originates from improper neutralization of special elements in user‑supplied data that is passed to an operating system command interpreter within Dell Secure Connect Gateway 5.0. The flaw allows an attacker who has low‑privileged local access to inject and execute arbitrary OS commands on the device, achieving full control of the affected appliance.
Affected Systems
Impact extends to all Dell Secure Connect Gateway 5.0 appliance and application versions older than 5.36.00.16 and 5.36.00.00 respectively. These products provide VPN and secure connectivity services for enterprise environments, and any unpatched installation is susceptible to the command injection described.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, while the EPSS score of 2% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Exploitation requires local access with a low‑privileged account; once gained, an attacker can run arbitrary commands, potentially compromising confidentiality, integrity, and availability. The local nature of the attack vector reduces the likelihood of widespread compromise, but the ability to subvert the appliance warrants prompt remediation.
OpenCVE Enrichment