Impact
Dell Secure Connect Gateway versions prior to 5.36.00 are vulnerable to an insertion of sensitive information into debugging code, allowing a local attacker with low privilege to access confidential data. The flaw is a moderate severity confidentiality risk (CVSS 5.5) and does not affect remote users, but once local access is obtained the attacker can read sensitive debug output and potentially leak system credentials or configuration details. The vulnerability leverages improper handling of debug logs but does not allow arbitrary code execution or system compromise beyond information disclosure.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Users of these appliance or application components must confirm their installed versions against these thresholds.
Risk and Exploitability
The CVSS score of 5.5 rating this as a medium impact vulnerability and the absence of an EPSS rating or KEV listing indicate that it is not widely exploited in the wild yet. However, the need for local, low‑privileged access means the risk remains for environments where local users are not tightly controlled. The attack path requires the attacker to be physically or otherwise local to the device, then to trigger or read debugging output, which can reveal sensitive information. Given these constraints, the likelihood of exploitation is considered moderate but not negligible.
OpenCVE Enrichment