Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-09
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain an insertion of sensitive information into log files. A low‑privileged attacker who can access the system locally may exploit the weakness to read data from log files, potentially revealing confidential or privileged information. The vulnerability is classified as CWE-532, indicating that information is being revealed through exploitation of the logging mechanism.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance and Application. The issue exists in all releases before Appliance version 5.36.00.16 and Application version 5.36.00.00.

Risk and Exploitability

The CVSS score of 3.3 indicates low overall severity, and the EPSS score is currently unreported. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector requires local access and low privilege, the likelihood of exploitation is limited to users who have some local foothold or credential. However, should an attacker obtain such access, they could discover sensitive data in application logs. The lack of an identified public exploit at this time suggests a moderate risk, but mitigation through upgrading or configuration changes is recommended.

Generated by OpenCVE AI on September 9, 2026 at 16:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Appliance to version 5.36.00.16 or newer.
  • Upgrade Dell Secure Connect Gateway Application to version 5.36.00.00 or newer.
  • If upgrading immediately is not possible, review and, if feasible, disable or redact sensitive fields in log configuration to prevent sensitive data from being written to logs.

Generated by OpenCVE AI on September 9, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposed Through Log Files in Dell Secure Connect Gateway

Wed, 09 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:00:03.603Z

Reserved: 2026-08-25T21:04:22.134Z

Link: CVE-2026-80169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T13:20:43.050

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-80169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:30:05Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File