Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-09
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00, respectively, copy sensitive data into log files. A local attacker with low privileges can exploit this by triggering the logging operation, causing confidential information to be exposed through standard system logs. The vulnerability is rated low on the CVSS scale (3.3), indicating limited impact but still significant enough to compromise sensitive data if exploited. The weakness is a classic insertion of sensitive information into logs, as identified by CWE-532.

Affected Systems

Systems running Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 or Application versions earlier than 5.36.00.00 are affected. The vulnerability is limited to these product lines and applies to all environments where the default logging process records sensitive information.

Risk and Exploitability

The CVSS score of 3.3 classifies this issue as low severity; however, the attack requires local presence and low privilege, meaning that it is theoretically possible but not trivial. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been observed. Nonetheless, a local attacker can potentially expose sensitive data by forcing the application to log that data, making remediation a priority for environments that handle confidential information.

Generated by OpenCVE AI on September 9, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 update that patches the log‑injection flaw and brings the appliance to at least version 5.36.00.16 and the application to at least version 5.36.00.00.
  • Reconfigure logging settings to avoid recording sensitive data such as passwords or authentication tokens, or limit log retention to reduce exposure window.
  • Review existing log files for inadvertent disclosure of sensitive information and rotate or secure them appropriately.

Generated by OpenCVE AI on September 9, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Title CWE-532: Insertion of Sensitive Information into Log File
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:53:04.681Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79966

cve-icon Vulnrichment

Updated: 2026-09-09T12:52:59.439Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T13:20:39.380

Modified: 2026-09-09T20:11:02.547

Link: CVE-2026-79966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:30:07Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File