OS Command Injection in Dell SCG 5.0 Appliance and Application
CVE-2026-79641

7.5HIGH

What is CVE-2026-79641?

The Dell SCG 5.0 Appliance and Application versions prior to specified updates are susceptible to an OS Command Injection vulnerability. This flaw arises from improper handling of special elements in OS commands, allowing a low privileged remote attacker to execute arbitrary commands. If exploited, this vulnerability may permit the attacker to elevate their privileges within the system, potentially compromising the integrity and security of affected deployments.

Affected Version(s)

Secure Connect Gateway 5.0 - Appliance 0 < 5.36.00.16 or later

Secure Connect Gateway 5.0 - Application 0 < 5.36.00.00 or later

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.