Impact
The vulnerability is a cleartext storage of sensitive information flaw that allows a low privileged local attacker to access stored credentials or other confidential data on the device. This flaw is categorized under CWE-312 and results in confidentiality compromise. The affected component is the secure storage mechanism in Dell Secure Connect Gateway 5.0 whose sensitive data are persisted without encryption.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Devices running these versions are at risk of exposing sensitive information to local attackers.
Risk and Exploitability
The CVSS score of 5.5 classifies the issue as moderate severity. The EPSS score is not available, indicating no current public exploitation data, and the vulnerability is not listed in CISA KEV catalog. An attacker with low privileged local access could exploit this by accessing the device locally and reading the plaintext stored data. The risk is limited to information disclosure and does not directly impact service availability or integrity, but the exposure could be leveraged in further attacks.
OpenCVE Enrichment