Sceawere

Vulnerability Detail

CVE-2026-80056UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Sensitive Log Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-532: Insertion of Sensitive Information into Log File
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-07T15:17:32.277Z",
  "pubdate": "2026-09-07T15:17:32.277Z",
  "executiveSummary": "This vulnerability involves an Insertion of Sensitive Information into Log File flaw identified within Dell SCG 5.0 Appliance and Application versions.\nThe vulnerability occurs when sensitive data, such as credentials or protected system information, is improperly recorded in system log files in plaintext or insufficient masking formats.\nAffected systems include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nThe risk implication is unauthorized information exposure, potentially allowing a local attacker to harvest sensitive credentials or configuration details.\nExploitation requires a low-privileged attacker to possess local access to the appliance or application environment, enabling them to read log files that store the inadvertently cached sensitive data.\nSuccessful exploitation could facilitate privilege escalation or further compromise of the Dell SCG environment.",
  "technicalDetails": "The vulnerability is categorized as an Insertion of Sensitive Information into Log File issue, arising from improper sanitization or handling of sensitive data streams before they are persisted to local log files.\nThe root cause lies in the application's logging logic, which fails to scrub or redact sensitive metadata, tokens, or credentials during routine diagnostic or transactional logging operations.\nAn attacker with low-privileged local access can leverage this exposure by directly accessing log directories where the system writes its operational output. By querying these files, an attacker can extract plaintext data that should remain confidential.\nAttack flow begins with the attacker establishing a local session on the host system. Once authenticated with low-level privileges, the attacker targets specific log files or directories designated for SCG application logging. By performing search operations (such as grep or cat) on these files, the attacker can systematically identify and harvest credentials or sensitive state information leaked during previous application runtime cycles.\nThe vulnerability affects Dell SCG 5.0 Appliance (versions < 5.36.00.16) and Dell SCG 5.0 Application (versions < 5.36.00.00).\nPost-exploitation impact includes unauthorized disclosure of authentication tokens, API keys, or infrastructure configuration details, which an adversary could use to maintain persistence or escalate privileges within the Dell SCG ecosystem.\nThis vulnerability is particularly dangerous as log files are often stored with broad read permissions, facilitating access for lower-privileged users who have legitimate local system access. There is no requirement for network-level exploitation, as the primary vector remains the local system's filesystem."
}
CVE-2026-80056: Dell SCG Sensitive Log Exposure (MEDIUM Severity, CVSS: 5.5) - Sceawere