SQL Injection Vulnerability in Dell Secure Connect Gateway Application and Appliance
CVE-2024-51539
2.3LOW
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 25 February 2025
Summary
The Dell Secure Connect Gateway (SCG) Application and Appliance versions prior to 5.28 contain a SQL injection vulnerability due to improper handling of special elements in SQL commands. This vulnerability can be exploited locally by a high-privilege attacker with access to the affected system. If successfully exploited, it could lead to the disclosure of non-sensitive information, but it does not compromise customer data.
Affected Version(s)
Secure Connect Gateway - Appliance < 5.28.00
Secure Connect Gateway - Application < 5.28.00
References
CVSS V3.1
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
CVE-2024-51539: Dell would like to thank saltedfish for reporting this issue.