Executive brief
Dell Secure Connect Gateway (SCG) 5.0 is a network appliance and application that manages secure remote connectivity for enterprise users. A vulnerability allows a low-privileged attacker with local access to read sensitive information that has been stored in a world-accessible file or directory, potentially exposing credentials, configuration details, or other confidential data.
Technical details
This vulnerability is classified as an Insertion of Sensitive Information into Externally-Accessible File or Directory (CWE-552). The root cause is improper file permission management in Dell SCG 5.0 Appliance (versions prior to 5.36.00.16) and Application (versions prior to 5.36.00.00), where sensitive data is written to files or directories accessible to unprivileged users. Attack requires local access to the affected system; an attacker with a low-privilege account can read exposed sensitive information without additional authentication. Dell has patched this vulnerability in version 5.36.00.16 for Appliance and 5.36.00.00 for Application.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed