Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Patch
AI Analysis

Impact

The vulnerability allows the insertion of sensitive user credentials and other confidential data into log files generated by Dell Secure Connect Gateway 5.0. This issue arises when the software writes server activity logs that inadvertently include passwords, tokens, or other protected information. The impact is limited to information disclosure; it does not enable code execution or denial of service. The weakness is classified as CWE‑532. Because the description does not confirm whether the default logging configuration includes these fields, it is inferred that logs may contain sensitive data if the system is configured to record detailed session information.

Affected Systems

This problem affects Dell Secure Connect Gateway Appliance versions earlier than 5.36.00.16 and Secure Connect Gateway Application versions earlier than 5.36.00.00. Any deployment running one of these versions is potentially exposed if it writes detailed logs.

Risk and Exploitability

The CVSS base score of 5.5 indicates a moderate risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access and only low privileges; they could trigger the logging of a transaction that contains sensitive data and then read the resulting log files to obtain the disclosed information. The likelihood of exploitation depends on the presence of detailed logging and the number of local users with minimal privileges on the affected system.

Generated by OpenCVE AI on September 7, 2026 at 16:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway security update to version 5.36.00.16 for the Appliance or 5.36.00.00 for the Application
  • If an immediate update is unavailable, reconfigure the system’s logging to suppress sensitive fields such as passwords and authentication tokens
  • Reduce local user privileges to the minimum required for normal operation to limit the impact of a local low‑privileged attacker

Generated by OpenCVE AI on September 7, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell secure Connect Gateway

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T12:48:28.606Z

Reserved: 2026-08-25T18:04:39.714Z

Link: CVE-2026-80056

cve-icon Vulnrichment

Updated: 2026-09-08T12:48:25.622Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T15:17:32.277

Modified: 2026-09-11T21:22:05.523

Link: CVE-2026-80056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File