Impact
The vulnerability arises from improper neutralization of special elements used in an OS command, enabling an attacker who has low‑privileged remote access to inject commands that are executed by the Dell Secure Connect Gateway 5.0 Appliance or Application. Successful injection can lead to elevation of privileges and potentially full control over the deployment.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00 are susceptible. The weakness exists in both the appliance and application components.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity risk. No EPSS score is listed, and the vulnerability is not in the CISA KEV catalog. The attack vector is inferred to be remote; an adversary must obtain a low‑privileged connection to the Gateway before crafting and injecting malicious commands. Once executed, the attacker may gain elevated privileges and compromise the system's integrity and confidentiality.
OpenCVE Enrichment