Impact
Dell Secure Connect Gateway 5.0 contains an OS command injection flaw that can be exploited by unauthenticated attackers who have remote network access. By leveraging the improper neutralization of special elements, an attacker can inject and execute arbitrary shell commands on the gateway appliance or application. This flaw maps to CWE‑78 and could allow full compromise of the device, resulting in loss of confidentiality, integrity, and availability for the connected network.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. These versions lack the patch that mitigates the command injection vulnerability.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score is currently unavailable and the vulnerability is not listed in CISA KEV. An attacker requires only remote access with no authentication, making the attack vector straightforward. Although the exploit probability is uncertain due to missing EPSS data, the potential impact of remote code execution warrants prompt remediation.
OpenCVE Enrichment