Impact
The vulnerability allows an attacker with low privileges and local access to insert confidential information into log files on Dell Secure Connect Gateway appliances and applications. By manipulating log entries, the attacker can cause sensitive data—such as authentication credentials, tokens, and configuration details—to be recorded in plain text, enabling accidental disclosure to anyone with read access to the logs. The impact is therefore the exposure of confidential information rather than denial‑of‑service or code execution.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. These versions contain the log‑injection flaw that can be triggered via local access.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. The likely attack vector is local; an attacker must have physical or network access that allows them to log in with low privileged credentials. Given that the flaw does not enable remote code execution or privilege escalation, the overall risk to the system is limited to potential information leakage for users with local access.
OpenCVE Enrichment