SQL Injection Vulnerability in Dell Secure Connect Gateway Application and Appliance
CVE-2024-51539

2.3LOW

Key Information:

Summary

The Dell Secure Connect Gateway (SCG) Application and Appliance versions prior to 5.28 contain a SQL injection vulnerability due to improper handling of special elements in SQL commands. This vulnerability can be exploited locally by a high-privilege attacker with access to the affected system. If successfully exploited, it could lead to the disclosure of non-sensitive information, but it does not compromise customer data.

Affected Version(s)

Secure Connect Gateway - Appliance < 5.28.00

Secure Connect Gateway - Application < 5.28.00

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CVE-2024-51539: Dell would like to thank saltedfish for reporting this issue.
.