Executive brief
Dell Secure Connect Gateway is a network security appliance used to manage secure remote access and connections. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) leave sensitive system information exposed through uncleared debug output. An attacker with physical access to the device could potentially retrieve this debug information, compromising operational security and potentially exposing credentials or system configuration details.
Technical details
This vulnerability involves the exposure of sensitive system information due to uncleared debug information remaining in the Dell SCG product. The root cause is improper cleanup of debugging data during normal operation or upon system startup. An unauthenticated attacker requires physical access to the appliance to exploit this vulnerability. Successful exploitation could lead to disclosure of sensitive system information such as configuration details, credentials, or internal state data that could be used in further attacks. Patches are available in Dell SCG 5.0 Appliance versions 5.36.00.16 and later, and Dell SCG 5.0 Application versions 5.36.00.00 and later.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: CVE-2026-80239 published