CVE-2026-78482: SQL Injection
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell SCG 5.0 Applianceto a version that resolves this vulnerability.Fixed in 5.36.00.16 - Upgrade
Upgrade
Dell SCG 5.0 Applicationto a version that resolves this vulnerability.Fixed in 5.36.00.00
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to the affected Dell SCG 5.0 system and low-privileged access. The provided information does not indicate that remote unauthenticated attackers can exploit it.
Which releases need to be updated?
Dell SCG 5.0 Appliance versions earlier than 5.36.00.16 and Dell SCG 5.0 Application versions earlier than 5.36.00.00 are affected. Updating to at least those versions addresses the listed affected version ranges.
What is the potential impact after exploitation?
Successful exploitation could allow OS command execution. The vulnerability information lists confidentiality impact as high, with no integrity or availability impact indicated.