Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information Into Debugging Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-09
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway versions prior to 5.36.00 are vulnerable to an insertion of sensitive information into debugging code, allowing a local attacker with low privilege to access confidential data. The flaw is a moderate severity confidentiality risk (CVSS 5.5) and does not affect remote users, but once local access is obtained the attacker can read sensitive debug output and potentially leak system credentials or configuration details. The vulnerability leverages improper handling of debug logs but does not allow arbitrary code execution or system compromise beyond information disclosure.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Users of these appliance or application components must confirm their installed versions against these thresholds.

Risk and Exploitability

The CVSS score of 5.5 rating this as a medium impact vulnerability and the absence of an EPSS rating or KEV listing indicate that it is not widely exploited in the wild yet. However, the need for local, low‑privileged access means the risk remains for environments where local users are not tightly controlled. The attack path requires the attacker to be physically or otherwise local to the device, then to trigger or read debugging output, which can reveal sensitive information. Given these constraints, the likelihood of exploitation is considered moderate but not negligible.

Generated by OpenCVE AI on September 9, 2026 at 13:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s security update DSA‑2026‑382 to upgrade Secure Connect Gateway Appliance to at least 5.36.00.16 and Application to at least 5.36.00.00.
  • Disable or remove any enabled debugging or log‑output settings that expose sensitive data in the appliance or application configuration files.
  • Limit local user accounts to the minimum privileges required, enforcing the principle of least privilege and restricting access to administrative functions.

Generated by OpenCVE AI on September 9, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Leakage via Debugging Code in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information Into Debugging Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-215
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:53:42.333Z

Reserved: 2026-08-25T12:04:33.630Z

Link: CVE-2026-79694

cve-icon Vulnrichment

Updated: 2026-09-09T12:53:38.655Z

cve-icon NVD

Status : Received

Published: 2026-09-09T13:20:37.830

Modified: 2026-09-09T13:20:37.830

Link: CVE-2026-79694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:30:10Z

Weaknesses
  • CWE-215

    Insertion of Sensitive Information Into Debugging Code