Impact
This vulnerability is an improper neutralization of special elements used in an SQL command, enabling a remote attacker with high privileges to conduct a SQL injection attack against Dell Secure Connect Gateway 5.0. The injection could allow the attacker to alter or retrieve data stored in the underlying database, leading to unauthorized access to configuration settings or sensitive information. The weakness is identified as CWE-89. No additional code execution is explicitly described, but the possibility of gaining privileged database access constitutes a serious breach of confidentiality and integrity for the affected system.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance and Application firmware versions prior to 5.36.00.16 and 5.36.00.00, respectively, are impacted. Any deployment of these older versions remains at risk until the latest patch is applied.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score is not available, so precise exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV, implying no confirmed widespread exploitation yet. The likely attack vector is remote, requiring an attacker to have high privileged remote access to the gateway—either through a compromised management interface or an exposed administrative endpoint. Once accessed, the attacker could exploit the SQL injection to manipulate or read privileged data.
OpenCVE Enrichment