Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows the insertion of sensitive user credentials and other confidential data into log files generated by Dell Secure Connect Gateway 5.0. This issue arises when the software writes server activity logs that inadvertently include passwords, tokens, or other protected information. The impact is limited to information disclosure; it does not enable code execution or denial of service. The weakness is classified as CWE‑532. Because the description does not confirm whether the default logging configuration includes these fields, it is inferred that logs may contain sensitive data if the system is configured to record detailed session information.

Affected Systems

This problem affects Dell Secure Connect Gateway Appliance versions earlier than 5.36.00.16 and Secure Connect Gateway Application versions earlier than 5.36.00.00. Any deployment running one of these versions is potentially exposed if it writes detailed logs.

Risk and Exploitability

The CVSS base score of 5.5 indicates a moderate risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access and only low privileges; they could trigger the logging of a transaction that contains sensitive data and then read the resulting log files to obtain the disclosed information. The likelihood of exploitation depends on the presence of detailed logging and the number of local users with minimal privileges on the affected system.

Generated by OpenCVE AI on September 7, 2026 at 16:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway security update to version 5.36.00.16 for the Appliance or 5.36.00.00 for the Application
  • If an immediate update is unavailable, reconfigure the system’s logging to suppress sensitive fields such as passwords and authentication tokens
  • Reduce local user privileges to the minimum required for normal operation to limit the impact of a local low‑privileged attacker

Generated by OpenCVE AI on September 7, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T14:16:23.457Z

Reserved: 2026-08-25T18:04:39.714Z

Link: CVE-2026-80056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T15:17:32.277

Modified: 2026-09-07T15:17:32.277

Link: CVE-2026-80056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:15:17Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File