CVE-2026-78484: Command Injection
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell SCG 5.0 Applianceto a version that resolves this vulnerability.Fixed in 5.36.00.16 - Upgrade
Upgrade
Dell SCG 5.0 Applicationto a version that resolves this vulnerability.Fixed in 5.36.00.00
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs local access to the affected system and low-privileged credentials. The provided information does not indicate that remote unauthenticated attackers can exploit it.
Which releases need to be updated?
Dell SCG 5.0 Appliance versions earlier than 5.36.00.16 are affected, as are Dell SCG 5.0 Application versions earlier than 5.36.00.00.
What is the potential impact if exploitation succeeds?
Successful exploitation could allow execution of operating-system commands. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.