Sceawere
Vulnerability Detail
CVE-2026-80058UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Cleartext Information Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-312: Cleartext Storage of Sensitive Information
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-07T17:17:25.210Z",
"pubdate": "2026-09-07T17:17:25.210Z",
"executiveSummary": "This vulnerability involves the improper storage of sensitive information in cleartext within Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions.\nThe vulnerability is classified as a Cleartext Storage of Sensitive Information flaw, which allows locally authenticated, low-privileged attackers to gain unauthorized access to credentials or configuration data stored in an unprotected state.\nThe impact of this vulnerability is significant, as it facilitates unauthorized information disclosure, potentially leading to further compromise of the appliance's security posture or connected backend infrastructure.\nAffected products include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nThe risk implication is categorized as a security exposure where sensitive data is rendered readable due to insufficient encryption or obfuscation at rest.\nSuccessful exploitation requires the attacker to have pre-existing local access to the appliance or host environment, bypassing the need for remote network exploitation.",
"technicalDetails": "The root cause of the vulnerability resides in the application's design, which fails to implement cryptographic protection (such as encryption at rest or secure vaulting mechanisms) for sensitive data files residing within the filesystem.\nWhen sensitive parameters—such as administrative credentials, API keys, or configuration secrets—are stored in cleartext, the confidentiality of these assets is maintained solely by filesystem-level access controls.\nIf an attacker successfully authenticates to the underlying operating system of the Dell SCG Appliance with low privileges, they can traverse the file directory structure to locate these sensitive artifacts.\nThe exploitation flow follows a logical progression: first, the attacker establishes local shell access through valid credentials or an auxiliary local vulnerability. Second, the attacker performs reconnaissance on the filesystem to identify configuration files or storage directories associated with the SCG application.\nThird, once the specific file paths containing the sensitive cleartext data are identified, the attacker utilizes standard shell commands (e.g., 'cat', 'less', or 'grep') to read the contents of these files.\nBecause the information is stored without any form of transformation, decryption, or hashing, the payload is retrieved instantly by the attacker in its original, human-readable format.\nThis exposure persists because the Dell SCG application relies on inherent system-level directory permissions which may be insufficient to prevent a low-privileged user from reading data designated as 'sensitive'.\nPost-exploitation impact includes lateral movement or privilege escalation if the retrieved credentials belong to higher-privileged administrative accounts. Furthermore, if the exposed secrets are used for communication with other Dell backend services, the attacker may masquerade as the appliance to perform unauthorized API calls or exfiltrate data from integrated service accounts.\nThis vulnerability is present in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, confirming that the insecure storage mechanism was historically integrated into the appliance's codebase."
}