Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance used to provide secure remote access and connectivity. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain a vulnerability where sensitive information is embedded in debugging code, allowing a low-privileged attacker with local access to read this data and expose confidential information.
Technical details
This vulnerability is classified as an Insertion of Sensitive Information Into Debugging Code (CWE-215). The affected versions of Dell SCG 5.0 Appliance (prior to 5.36.00.16) and Application (prior to 5.36.00.00) include sensitive data such as credentials or configuration secrets in debug logging or output. An attacker with local access and low privileges can read these debug outputs to extract sensitive information. The attack vector is local, requiring some level of access to the system. Patches are available in versions 5.36.00.16 (appliance) and 5.36.00.00 (application) and later.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Versions 5.36.00.16 (appliance) and 5.36.00.00 (application) contain fixes