Impact
The vulnerability is an OS command injection caused by improper neutralization of special characters, allowing a low‑privileged attacker with local access to craft input that leads to arbitrary command execution on the host. This can compromise confidentiality, integrity, and availability of the affected system, but the description does not state that full system compromise is guaranteed.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are susceptible. All earlier releases before these patch levels contain the vulnerability.
Risk and Exploitability
The CVSS score of 5.5 signals a moderate severity. Because the EPSS score is unavailable and the vulnerability is not listed in KEV, exploitation likelihood appears low but not negligible. The attack vector is local, requiring that an attacker have low‑privileged access to the system. Once local access is achieved, adversaries could execute arbitrary commands, potentially elevating privileges or compromising data.
OpenCVE Enrichment