Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-09
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker with low privileges and local access to insert confidential information into log files on Dell Secure Connect Gateway appliances and applications. By manipulating log entries, the attacker can cause sensitive data—such as authentication credentials, tokens, and configuration details—to be recorded in plain text, enabling accidental disclosure to anyone with read access to the logs. The impact is therefore the exposure of confidential information rather than denial‑of‑service or code execution.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. These versions contain the log‑injection flaw that can be triggered via local access.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. The likely attack vector is local; an attacker must have physical or network access that allows them to log in with low privileged credentials. Given that the flaw does not enable remote code execution or privilege escalation, the overall risk to the system is limited to potential information leakage for users with local access.

Generated by OpenCVE AI on September 9, 2026 at 10:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later
  • Update Dell Secure Connect Gateway Application to version 5.36.00.00 or later
  • Review and sanitize log configurations to avoid storing sensitive data in log files
  • Restrict local privileges to reduce the pool of accounts that can trigger the log‑injection

Generated by OpenCVE AI on September 9, 2026 at 10:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Local Log Injection Exposes Sensitive Information in Dell Secure Connect Gateway

Wed, 09 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T07:55:05.193Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T08:17:22.510

Modified: 2026-09-09T08:17:22.510

Link: CVE-2026-80124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:15:09Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File