CVE-2026-80174
Analyzed Analyzed - Analysis Complete

Insufficient Session Expiration in Dell SCG 5.0

Vulnerability report for CVE-2026-80174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: Dell

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dell secure_connect_gateway to 5.36.00.00 (exc)
dell secure_connect_gateway to 5.36.00.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insufficient Session Expiration issue in Dell SCG 5.0 Appliance and Application versions before 5.36.00.16 and 5.36.00.00 respectively. It allows a low-privileged remote attacker to steal active user sessions due to improper session timeout handling.

Detection Guidance

This vulnerability involves insufficient session expiration in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Detection requires checking the installed version of the Dell Secure Connect Gateway (SCG) software or appliance. Use the following commands to verify the version: For the appliance, check the web interface or run system-specific commands like 'show version' or 'cat /etc/version' depending on the OS. For the application, inspect installed packages using commands like 'rpm -qa | grep dell' or 'dpkg -l | grep dell' on Linux systems. If the version is below the specified patched versions, the system is vulnerable.

Impact Analysis

An attacker could hijack an active user session to gain unauthorized access to sensitive data or perform actions on behalf of the legitimate user. This could lead to data breaches, unauthorized modifications, or further network compromise depending on user privileges.

Compliance Impact

This vulnerability could violate compliance requirements that mandate session timeout controls to protect sensitive data, such as GDPR's data protection principles or HIPAA's safeguards for protected health information. Failure to address it may result in non-compliance penalties.

Mitigation Strategies

Update Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later to address the Insufficient Session Expiration vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart