Impact
The vulnerability is a command injection flaw arising from improper neutralization of special elements used in commands. An unauthenticated attacker with remote access can inject and execute arbitrary scripts against the Dell Secure Connect Gateway 5.0 Appliance or Application, potentially compromising confidentiality, integrity, or availability of the system.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The flaw exists in both the appliance and application components of the Secure Connect Gateway 5.0 product line.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote, through unauthenticated access to command interfaces exposed by the gateway. If exploited, an attacker could perform arbitrary command execution and script injection on the device.
OpenCVE Enrichment