Executive brief
Dell Secure Connect Gateway is an appliance and application used for secure remote access and network connectivity. The vulnerability allows a low-privileged local attacker to insert sensitive information into log files, potentially exposing confidential data such as credentials or authentication tokens. This could lead to unauthorized access or further system compromise if logs are not properly protected.
Technical details
This vulnerability is an Insertion of Sensitive Information into Log File (CWE-532) in Dell Secure Connect Gateway. The flaw allows a low-privileged attacker with local access to insert or expose sensitive data within application logs. The attack vector is local with low privileges required, meaning an authenticated but unprivileged user can trigger the issue. The impact is information disclosure—sensitive data written to logs may be accessible to other users or processes with log file access. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and SCG 5.0 Application version 5.36.00.00 or later.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed