Impact
The vulnerability is an OS Command Injection caused by improper neutralization of special elements in command strings. A high privileged attacker who can remotely reach the device can exploit it, potentially executing arbitrary system commands and raising their privileges within the Secure Connect Gateway environment. This elevates the risk from a local issue to a significant local privilege escalation threat.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The issue applies to both the appliance and the application components of the product line.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium‑to‑high severity impact. No EPSS score is reported, and the vulnerability is not listed in KEV, suggesting that it has not yet been widely exploited but could be a target. The likely attack vector is remote access with elevated privileges, meaning that attackers who gain remote entry could leverage the injection to gain higher privileges locally. The lack of public exploitation data means the threat is considered moderate, but the potential for privilege escalation warrants prompt remediation.
OpenCVE Enrichment