Impact
The vulnerability allows the insertion of sensitive user credentials and other confidential data into log files generated by Dell Secure Connect Gateway 5.0. This issue arises when the software writes server activity logs that inadvertently include passwords, tokens, or other protected information. The impact is limited to information disclosure; it does not enable code execution or denial of service. The weakness is classified as CWE‑532. Because the description does not confirm whether the default logging configuration includes these fields, it is inferred that logs may contain sensitive data if the system is configured to record detailed session information.
Affected Systems
This problem affects Dell Secure Connect Gateway Appliance versions earlier than 5.36.00.16 and Secure Connect Gateway Application versions earlier than 5.36.00.00. Any deployment running one of these versions is potentially exposed if it writes detailed logs.
Risk and Exploitability
The CVSS base score of 5.5 indicates a moderate risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access and only low privileges; they could trigger the logging of a transaction that contains sensitive data and then read the resulting log files to obtain the disclosed information. The likelihood of exploitation depends on the presence of detailed logging and the number of local users with minimal privileges on the affected system.
OpenCVE Enrichment