Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is a cleartext storage of sensitive information flaw that allows a low privileged local attacker to access stored credentials or other confidential data on the device. This flaw is categorized under CWE-312 and results in confidentiality compromise. The affected component is the secure storage mechanism in Dell Secure Connect Gateway 5.0 whose sensitive data are persisted without encryption.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. Devices running these versions are at risk of exposing sensitive information to local attackers.

Risk and Exploitability

The CVSS score of 5.5 classifies the issue as moderate severity. The EPSS score is not available, indicating no current public exploitation data, and the vulnerability is not listed in CISA KEV catalog. An attacker with low privileged local access could exploit this by accessing the device locally and reading the plaintext stored data. The risk is limited to information disclosure and does not directly impact service availability or integrity, but the exposure could be leveraged in further attacks.

Generated by OpenCVE AI on September 7, 2026 at 17:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Appliance to version .36.00.16 or later and Application to 5.36.00.00 or later following the Dell security update documentation.
  • Limit local access by enforcing least‑privilege accounts and restricting physical or network access to the device.
  • Reconfigure or remove any features that store sensitive data in plaintext; if necessary, encrypt stored credentials and ensure proper secure handling.
  • Consult Dell’s security update article for detailed patching steps and any additional mitigation guidance.

Generated by OpenCVE AI on September 7, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell secure Connect Gateway

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Sensitive Information in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T14:45:55.300Z

Reserved: 2026-08-25T18:04:39.714Z

Link: CVE-2026-80058

cve-icon Vulnrichment

Updated: 2026-09-09T14:45:45.464Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T17:17:25.210

Modified: 2026-09-16T01:13:22.590

Link: CVE-2026-80058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information