Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance that manages secure connections for enterprise networks. A flaw in session handling allows attackers to reuse stolen sessions indefinitely, potentially gaining unauthorized access to the gateway and the systems it protects. This could lead to data breaches, network compromise, and operational disruption.
Technical details
The vulnerability is an insufficient session expiration flaw in Dell SCG 5.0 that allows sessions to persist indefinitely without proper timeout or invalidation mechanisms. A low-privileged attacker with remote network access can intercept or hijack active sessions and reuse them to maintain unauthorized access to the appliance. Unlike the concurrent CVE-2026-80172 (which requires no authentication), this flaw requires an existing session but provides a persistent backdoor once obtained. No nonce validation or time-based expiration prevents session replay. Patches are available in SCG Appliance version 5.36.00.16 and Application version 5.36.00.00 and later.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed