Sceawere
Vulnerability Detail
CVE-2026-80056UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Sensitive Log Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-532: Insertion of Sensitive Information into Log File
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-07T15:17:32.277Z",
"pubdate": "2026-09-07T15:17:32.277Z",
"executiveSummary": "This vulnerability involves an Insertion of Sensitive Information into Log File flaw identified within Dell SCG 5.0 Appliance and Application versions.\nThe vulnerability occurs when sensitive data, such as credentials or protected system information, is improperly recorded in system log files in plaintext or insufficient masking formats.\nAffected systems include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nThe risk implication is unauthorized information exposure, potentially allowing a local attacker to harvest sensitive credentials or configuration details.\nExploitation requires a low-privileged attacker to possess local access to the appliance or application environment, enabling them to read log files that store the inadvertently cached sensitive data.\nSuccessful exploitation could facilitate privilege escalation or further compromise of the Dell SCG environment.",
"technicalDetails": "The vulnerability is categorized as an Insertion of Sensitive Information into Log File issue, arising from improper sanitization or handling of sensitive data streams before they are persisted to local log files.\nThe root cause lies in the application's logging logic, which fails to scrub or redact sensitive metadata, tokens, or credentials during routine diagnostic or transactional logging operations.\nAn attacker with low-privileged local access can leverage this exposure by directly accessing log directories where the system writes its operational output. By querying these files, an attacker can extract plaintext data that should remain confidential.\nAttack flow begins with the attacker establishing a local session on the host system. Once authenticated with low-level privileges, the attacker targets specific log files or directories designated for SCG application logging. By performing search operations (such as grep or cat) on these files, the attacker can systematically identify and harvest credentials or sensitive state information leaked during previous application runtime cycles.\nThe vulnerability affects Dell SCG 5.0 Appliance (versions < 5.36.00.16) and Dell SCG 5.0 Application (versions < 5.36.00.00).\nPost-exploitation impact includes unauthorized disclosure of authentication tokens, API keys, or infrastructure configuration details, which an adversary could use to maintain persistence or escalate privileges within the Dell SCG ecosystem.\nThis vulnerability is particularly dangerous as log files are often stored with broad read permissions, facilitating access for lower-privileged users who have legitimate local system access. There is no requirement for network-level exploitation, as the primary vector remains the local system's filesystem."
}