Impact
The vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, also known as a SQL Injection flaw. A low privileged attacker who can reach the device remotely could inject SQL statements into the application, potentially leading to unauthorized access or execution of arbitrary commands within the database context. The flaw allows the attacker to bypass authentication or glean sensitive data, directly compromising the confidentiality and integrity of the system.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00 are affected. The products include the appliance and application components of the Dell Secure Connect Gateway 5.0 platform.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, with no EPSS data and the vulnerability not listed in the CISA KEV catalogue. The likely attack vector is a remote attacker who can reach the appliance or application over the network with low privileges. Given the remote nature, exploitation could occur without local network compromise, but an attacker would need to identify a vulnerable instance first.
OpenCVE Enrichment