Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application used to provide secure remote access and connections. Uncleared debug information in affected versions allows a low-privileged attacker with local system access to read sensitive system information that could aid in further compromise of the appliance or network infrastructure.
Technical details
The vulnerability is an information exposure flaw in Dell SCG 5.0 caused by debug information that is not properly cleared from the system. The vulnerable component retains sensitive system data in debug output or files accessible to local users. A low-privileged local attacker (e.g., an unprivileged system user) can read this debug information to extract sensitive system details. The attack requires local access to the appliance or application instance and low privilege level, making it actionable in scenarios where the attacker has already gained a foothold on the system. Remediation is available by upgrading to patched versions (5.36.00.16 for Appliance or 5.36.00.00 for Application).
Affected products
- Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
- Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed