Impact
The vulnerability is an OS Command Injection flaw that allows a low‐privileged attacker with remote access to inject arbitrary commands into the operating system. If exploited, the attacker could gain unauthorized code execution, compromising the confidentiality, integrity, and availability of the affected systems. The weakness is formally identified as CWE‑78, which is a type of improper neutralization of special elements used in OS command generation.
Affected Systems
The vulnerability affects Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00. These are Dell appliances and application software used to provide secure connectivity as part of VMware Cloud services.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no current exploit data has been reported. The likely attack vector is remote access from a low‑privileged user to the appliance or application, which can then inject commands via exposed interfaces. Because the flaw permits arbitrary command execution, an attacker could potentially take full control of the affected device.
OpenCVE Enrichment