Impact
Dell Secure Connect Gateway 5.0 Appliance and Application versions before 5.36.00.16 and 5.36.00.00 respectively allow exposure of sensitive system information through uncleared debug logs. An attacker with local, low‑privileged access could read this diagnostic data, potentially revealing configuration details, credentials, or other sensitive information. The weakness is identified as CWE-1258, which concerns failure to remove debug information that should not be disclosed.
Affected Systems
Dell Secure Connect Gateway Appliance 5.0 prior to version 5.36.00.16 and Dell Secure Connect Gateway Application 5.0 prior to version 5.36.00.00. The vulnerability exists in all builds preceding the listed release numbers.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score is currently unavailable, suggesting limited publicly known exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack is possible only with local, low‑privileged access; there is no remote exploitation vector disclosed. Nevertheless, denial of confidentiality can affect system integrity and audit confidence, so the risk is considered low to moderate depending on the sensitivity of the exposed data.
OpenCVE Enrichment