CVE-2024-51539

T

he Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This vulnerability can only be exploited locally on the affected system. A high-privilege attacker with access to the system could potentially exploit this vulnerability, leading to the disclosure of non-sensitive information that does not include any customer data.

Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*

History

21 Jan 2026, 22:02

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000289550/dsa-2024-464-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000289550/dsa-2024-464-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerability - Vendor Advisory
CPE cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
Summary
  • (es) La aplicación y el dispositivo Dell Secure Connect Gateway (SCG), versiones anteriores a la 5.28, contienen una vulnerabilidad de inyección SQL debido a la neutralización incorrecta de elementos especiales utilizados en un comando SQL. Esta vulnerabilidad solo se puede explotar de forma local en el sistema afectado. Un atacante con privilegios elevados y acceso al sistema podría explotar esta vulnerabilidad, lo que provocaría la divulgación de información no confidencial que no incluye ningún dato del cliente.
First Time Dell
Dell secure Connect Gateway

25 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-25 14:15

Updated : 2026-01-21 22:02


NVD link : CVE-2024-51539

Mitre link : CVE-2024-51539

CVE.ORG link : CVE-2024-51539


JSON object : View

Products Affected
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')