Impact
The vulnerability is an Improper Neutralization of Special Elements used in a Command, identified as CWE‑77. In Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16 and Application prior to 5.36.00.00, user input that is passed to system commands is not properly sanitized, allowing an attacker to inject malicious script or command sequences. This can lead to the execution of unintended commands on the device. The description indicates that the effect is a script injection that could potentially result in arbitrary code execution, but the exact outcome depends on the device’s configuration and the commands that are invoked.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance and Application are affected. All builds earlier than 5.36.00.16 for the appliance and earlier than 5.36.00.00 for the application contain the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS score is 4% and the vulnerability is not listed in the CISA KEV catalog. Attackers require only remote network connectivity and do not need authentication; the likely attack vector is remote network access. While no public exploit is documented, the possibility of executing arbitrary commands after injection provides substantial impact, potentially leading to remote code execution in the right circumstances.
OpenCVE Enrichment