Impact
Dell Secure Connect Gateway 5.0 Appliance and Application versions earlier than 5.36.00.16 and 5.36.00.00 contain an OS Command Injection flaw caused by improper neutralization of special elements used in an operating‑system command. An attacker with unauthenticated remote access could inject shell commands, potentially leading to script injection on the gateway.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected patch that mitigates the command injection vulnerability.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score is 5% and the vulnerability is not listed in CISA KEV. An attacker requires only remote access with no authentication, making the attack vector straightforward. Although the EPSS score of 5% suggests a moderately low exploit probability, the potential impact of remote code execution warrants prompt remediation.
OpenCVE Enrichment