Impact
An OS Command Injection flaw allows a low‑privileged attacker with remote access to inject arbitrary operating‑system commands. If exploited, the attacker could execute arbitrary code on the device, compromising confidentiality, integrity, and availability. The weakness is formally identified as CWE‑78.
Affected Systems
The vulnerability impacts Dell Secure Connect Gateway 5.0 Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00, which provide secure connectivity services.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of 5% suggests a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can remotely reach the appliance or application with low privileges, then inject commands via exposed interfaces, allowing arbitrary code execution.
OpenCVE Enrichment