Executive brief
Dell Secure Connect Gateway (SCG) is a network security appliance and application that manages remote access and VPN connectivity for enterprise networks. A vulnerability in versions before 5.36.00.16 (appliance) and 5.36.00.00 (application) allows attackers with local system access to extract sensitive information from application log files, potentially exposing credentials or other confidential data that could be used for further attacks.
Technical details
This vulnerability is classified as an "Insertion of Sensitive Information into Log File" (CWE-532). The appliance and application log sensitive data (such as authentication tokens, credentials, or other confidential details) without proper sanitization. An attacker with low-privilege local access to the system can read these log files and extract the exposed information. This requires local file system access but does not require authentication to the SCG application itself. The vulnerability affects SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00; patches are available in these versions.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Patches available in version 5.36.00.16 (appliance) and 5.36.00.00 (application)