Impact
Dell Secure Connect Gateway 5.0 appliances and applications prior to versions 5.36.00.16 and 5.36.00.00 contain an OS Command Injection flaw. This weakness allows an attacker with low‑privileged local access to embed malicious commands into input fields that are processed by the system’s shell. If exploited, the attacker can execute arbitrary scripts or commands on the target device, potentially compromising system integrity and availability and providing a foothold for further lateral movement.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Administrators should confirm the running version of their appliances and applications.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is 2%, indicating a low but measurable exploitation probability, implying limited public exploitation data. The vulnerability is not listed in CISA KEV. Exploitation requires local access with low privileges; thus, an attacker must have physical or local network access to the device. Once achieved, they can inject shell commands, leading to partial compromise of the gateway’s operating system.
OpenCVE Enrichment