---
id: CVE-2026-80174
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Insufficient Session
  Expiration vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Insufficient Session
  Expiration vulnerability. A low privileged attacker with remote access could
  potentially expl…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-613
vendor: Dell
product: Secure Connect Gateway 5.0 - Application
affected:
  - secure_connect_gateway_5.0_-_application < 5.36.00.00 or later
  - secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T13:05:00.689514Z'
published: '2026-09-09'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T13:05:10.859Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-80174'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
tags:
  - cve.org
epss: 0.00272
epssPercentile: 0.17485
ingestedAt: '2026-09-14T15:23:07.426Z'
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.

## Affected

- `secure_connect_gateway_5.0_-_application < 5.36.00.00 or later`
- `secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
