Impact
This vulnerability is an Improper Neutralization of Alternate XSS Syntax flaw. An attacker who can send input to the affected web interfaces could inject unsolicited scripts. The injected code would be executed in the browser context of users who view the affected content, potentially allowing the attacker to steal session cookies, deface the application, or perform further malicious actions.
Affected Systems
Dell Secure Connect Gateway 5.0 appliance, versions earlier than 5.36.00.16, and Dell Secure Connect Gateway 5.0 application, versions earlier than 5.36.00.00
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. According to the description, the attack vector is remote access to the web interface and the attacker does not need authentication. The exploitation can result in user‑side script execution, which can compromise confidentiality and integrity of data accessed by the victim browser. The lack of a public exploit and the need for unauthenticated remote submission moderate the likelihood of exploitation.
OpenCVE Enrichment