Impact
The vulnerability is an improper sanitization of custom special characters that allows a remote attacker to inject malicious script content. An unauthenticated user with network access to the Dell Secure Connect Gateway could supply crafted input that bypasses the system’s filtering, resulting in script execution on the targeted appliance or application.
Affected Systems
The flaw affects Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00. Users running these older releases should verify their install versions.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote, unauthenticated; the attacker would need only network access to the gateway to supply malicious input. The overall risk is moderate, but the absence of a known exploit does not preclude future exploitation.
OpenCVE Enrichment