Junglewise Threat Intelligence

CVE-2026-80058: Dell Secure Connect Gateway cleartext storage of sensitive information

CVE-2026-80058 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a remote access appliance used to provide secure connections to corporate networks. A low-privileged local attacker can exploit a cleartext storage vulnerability to expose sensitive information stored without encryption, potentially compromising credentials or other confidential data used by the system.

Technical details

The vulnerability is a cleartext storage of sensitive information issue (CWE-312) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. An attacker with local access and low privileges can read sensitive data stored in plaintext, bypassing encryption protections. The attack requires local system access but no elevated permissions or user interaction. Exploitation leads to exposure of confidential information. Dell has released patched versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to remediate this issue.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: CVE-2026-80058 published
  • 2026-09-07: patched: Patched versions: Appliance 5.36.00.16, Application 5.36.00.00

References

Related threats