Impact
Dell Secure Connect Gateway 5.0 stores passwords in clear text within the appliance and application, allowing a user with low privileges who has local access to read them. This flaw can lead to the disclosure of authentication credentials, compromising confidentiality and potentially enabling further attacks if those credentials are used for privileged accounts. The vulnerability is identified as CWE‑257 and rated with a CVSS score of 4.7.
Affected Systems
The issue affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and the Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Systems with these versions have been noted to store passwords unencrypted in configuration files or database entries; any local user with standard permissions can read those files.
Risk and Exploitability
The CVSS base score of 4.7 indicates a moderate risk, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. An attacker would need local access and the ability to log on as a low‑privileged user; from there the attacker could read stored credentials. Because the flaw does not require remote exploitation or elevated privileges, the immediate threat is limited to environments where local users have higher entropy than expected.
OpenCVE Enrichment