Impact
Dell Secure Connect Gateway 5.0 appliances and applications contain an Improper Neutralization of Special Elements used in an LDAP Query, known as LDAP injection. This weakness allows an unauthenticated attacker with remote access to construct malicious LDAP queries that can inject arbitrary script code. The impact may include unauthorized data access and the possibility of executing the injected scripts if the system processes them, potentially leading to further compromise.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The vulnerability applies to both the appliance and application components referenced by Dell.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity level, and no EPSS score is publicly available. This vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation at the time of this analysis. An attacker could potentially exploit the flaw remotely without authentication, but the lack of a high exploitability score reduces immediate risk. Organizations should consider the attack vector as remote and unauthenticated access to the LDAP service.
OpenCVE Enrichment