Impact
The vulnerability involves improper encoding or escaping of output, permitting an attacker to inject or manipulate content that can be used to launch phishing attacks. An unauthenticated attacker with remote access could exploit this flaw, causing malicious content to be displayed to targets. This weakness corresponds to CWE‑116, where insufficient output encoding undermines confidentiality and integrity of user interfaces.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance running versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application running versions earlier than 5.36.00.00.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, but the absence of an EPSS score and lack of listing in the KEV catalog suggest limited evidence of active exploitation. The likely attack vector is remote, with the attacker needing unauthenticated network access to the SCG services to exploit the output encoding flaw. Once exploited, the attacker could deceive users into interacting with malicious links or forms, potentially compromising user credentials or system integrity.
OpenCVE Enrichment