Impact
The vulnerability is an Improper Neutralization of Alternate XSS Syntax flaw that allows an attacker to inject malicious scripts via unsanitized input; based on the description, it is inferred that script execution could lead to session hijacking, data exfiltration or phishing attacks, and is identified as CWE-87.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected; these products provide secure gateway services and are deployed in many corporate environments.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; EPSS information is not available, so the probability of exploitation is uncertain; the vulnerability is not listed in CISA KEV, implying no known widescale exploits, but an unauthenticated attacker with remote access to the web interface could potentially exploit the flaw by injecting script payloads into the browser context.
OpenCVE Enrichment