Impact
Dell Secure Connect Gateway versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain an insertion of sensitive information into log files. A low‑privileged attacker who can access the system locally may exploit the weakness to read data from log files, potentially revealing confidential or privileged information. The vulnerability is classified as CWE-532, indicating that information is being revealed through exploitation of the logging mechanism.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance and Application. The issue exists in all releases before Appliance version 5.36.00.16 and Application version 5.36.00.00.
Risk and Exploitability
The CVSS score of 3.3 indicates low overall severity, and the EPSS score is currently unreported. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector requires local access and low privilege, the likelihood of exploitation is limited to users who have some local foothold or credential. However, should an attacker obtain such access, they could discover sensitive data in application logs. The lack of an identified public exploit at this time suggests a moderate risk, but mitigation through upgrading or configuration changes is recommended.
OpenCVE Enrichment