Impact
The vulnerability is an OS Command Injection flaw that allows an attacker with low privileges and local access to run arbitrary shell commands on Dell Secure Connect Gateway 5.0 appliances and applications. The improper neutralization of special elements in command strings could let the attacker gain control over the underlying operating system or execute privileged operations, potentially leading to a full compromise of the device.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. Systems running these versions could be exploited by local attackers who have limited privileges on the device. The vulnerability does not affect newer releases beyond the stated cut‑off versions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while no EPSS score is currently available. The vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at present. An attacker would need local access and low privileges; the flaw is exploitable from within the appliance or application context, making the attack surface limited to machines or users already on the same network or system.
OpenCVE Enrichment