Impact
Dell Secure Connect Gateway 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00, respectively, copy sensitive data into log files. A local attacker with low privileges can exploit this by triggering the logging operation, causing confidential information to be exposed through standard system logs. The vulnerability is rated low on the CVSS scale (3.3), indicating limited impact but still significant enough to compromise sensitive data if exploited. The weakness is a classic insertion of sensitive information into logs, as identified by CWE-532.
Affected Systems
Systems running Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 or Application versions earlier than 5.36.00.00 are affected. The vulnerability is limited to these product lines and applies to all environments where the default logging process records sensitive information.
Risk and Exploitability
The CVSS score of 3.3 classifies this issue as low severity; however, the attack requires local presence and low privilege, meaning that it is theoretically possible but not trivial. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been observed. Nonetheless, a local attacker can potentially expose sensitive data by forcing the application to log that data, making remediation a priority for environments that handle confidential information.
OpenCVE Enrichment