Impact
This flaw is an insufficient session expiration condition in Dell Secure Connect Gateway 5.0. A remote attacker who holds a low‑privileged account can maintain or hijack a valid session, thereby gaining unauthorized access to protected resources or acting on behalf of that user. The impact is a loss of session integrity and potential privilege escalation if the stolen session can perform privileged actions.
Affected Systems
Affected versions are Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00. Only installations of those older releases are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or unknown exploitation activity. The attack vector is remote and requires low privileges, so the risk is moderate but should be addressed promptly given the potential for session hijacking.
OpenCVE Enrichment