Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is an insufficient session expiration condition in Dell Secure Connect Gateway 5.0. A remote attacker who holds a low‑privileged account can maintain or hijack a valid session, thereby gaining unauthorized access to protected resources or acting on behalf of that user. The impact is a loss of session integrity and potential privilege escalation if the stolen session can perform privileged actions.

Affected Systems

Affected versions are Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00. Only installations of those older releases are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or unknown exploitation activity. The attack vector is remote and requires low privileges, so the risk is moderate but should be addressed promptly given the potential for session hijacking.

Generated by OpenCVE AI on September 9, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later. In addition, upgrade the Application version to 5.36.00.00 or later. Once running a patched version, verify that automatic session timeouts are enabled and configured to expire after an appropriate period.
  • As a temporary measure prior to patching, consider disabling or restricting low‑privileged user accounts that can access the gateway until the upgrade has been completed.
  • Configure the session timeout settings to enforce a shorter idle period, ensuring sessions expire promptly to reduce the window for hijacking.

Generated by OpenCVE AI on September 9, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient Session Expiration Enables Session Theft in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T10:27:31.606Z

Reserved: 2026-08-25T21:04:22.134Z

Link: CVE-2026-80174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T11:17:15.797

Modified: 2026-09-09T11:17:15.797

Link: CVE-2026-80174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration