Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Session theft via compromised session expiration
Action: Patch Now
AI Analysis

Impact

This flaw is an insufficient session expiration condition in Dell Secure Connect Gateway 5.0. A remote attacker who holds a low‑privileged account can maintain or hijack a valid session, thereby gaining unauthorized access to protected resources or acting on behalf of that user. The impact is a loss of session integrity and potential privilege escalation if the stolen session can perform privileged actions.

Affected Systems

Affected versions are Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00. Only installations of those older releases are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or unknown exploitation activity. The attack vector is remote and requires low privileges, so the risk is moderate but should be addressed promptly given the potential for session hijacking.

Generated by OpenCVE AI on September 9, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later. In addition, upgrade the Application version to 5.36.00.00 or later. Once running a patched version, verify that automatic session timeouts are enabled and configured to expire after an appropriate period.
  • As a temporary measure prior to patching, consider disabling or restricting low‑privileged user accounts that can access the gateway until the upgrade has been completed.
  • Configure the session timeout settings to enforce a shorter idle period, ensuring sessions expire promptly to reduce the window for hijacking.

Generated by OpenCVE AI on September 9, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient Session Expiration Enables Session Theft in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-14T13:05:10.859Z

Reserved: 2026-08-25T21:04:22.134Z

Link: CVE-2026-80174

cve-icon Vulnrichment

Updated: 2026-09-14T13:05:06.966Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T11:17:15.797

Modified: 2026-09-14T13:18:47.920

Link: CVE-2026-80174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration