Impact
Dell Secure Connect Gateway 5.0 appliances and applications contain an exposure of sensitive system information due to uncleared debug information. An attacker without authentication who gains physical access can obtain confidential data such as passwords, configuration details, or other system information. The vulnerability is classified as CWE‑1258, reflecting the presence of debug output that remains accessible to unauthorized users.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity impact; EPSS data is not available and the vulnerability is not in the CISA KEV catalog. However, the attack requires only physical proximity and no authentication, making it relatively easy to execute in environments where these devices are not physically secured. The resulting information exposure could support further attacks if the compromised data includes credentials or configuration settings.
OpenCVE Enrichment