ID

VAR-202502-2173


CVE

CVE-2024-51539


TITLE

Dell's secure connect gateway In SQL  Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120

DESCRIPTION

The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This vulnerability can only be exploited locally on the affected system. A high-privilege attacker with access to the system could potentially exploit this vulnerability, leading to the disclosure of non-sensitive information that does not include any customer data. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software

Trust: 1.62

sources: NVD: CVE-2024-51539 // JVNDB: JVNDB-2025-025120

AFFECTED PRODUCTS

vendor:dellmodel:secure connect gatewayscope:ltversion:5.28.00.00

Trust: 1.0

vendor:デルmodel:secure connect gatewayscope:eqversion: -

Trust: 0.8

vendor:デルmodel:secure connect gatewayscope: - version: -

Trust: 0.8

vendor:デルmodel:secure connect gatewayscope:eqversion:5.28.00.00

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120 // NVD: CVE-2024-51539

CVSS

SEVERITY

CVSSV2

CVSSV3

security_alert@emc.com: CVE-2024-51539
value: LOW

Trust: 1.0

OTHER: JVNDB-2025-025120
value: LOW

Trust: 0.8

security_alert@emc.com: CVE-2024-51539
baseSeverity: LOW
baseScore: 2.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.8
impactScore: 1.4
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-025120
baseSeverity: LOW
baseScore: 2.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120 // NVD: CVE-2024-51539

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.0

problemtype:SQL injection (CWE-89) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120 // NVD: CVE-2024-51539

PATCH

title:DSA-2024-464url:https://www.dell.com/support/kbdoc/en-us/000289550/dsa-2024-464-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120

EXTERNAL IDS

db:NVDid:CVE-2024-51539

Trust: 2.6

db:JVNDBid:JVNDB-2025-025120

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120 // NVD: CVE-2024-51539

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000289550/dsa-2024-464-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerability

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-51539

Trust: 0.8

sources: JVNDB: JVNDB-2025-025120 // NVD: CVE-2024-51539

SOURCES

db:JVNDBid:JVNDB-2025-025120
db:NVDid:CVE-2024-51539

LAST UPDATE DATE

2026-01-24T23:48:16.395000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2025-025120date:2026-01-23T05:20:00
db:NVDid:CVE-2024-51539date:2026-01-21T22:02:45.997

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2025-025120date:2026-01-23T00:00:00
db:NVDid:CVE-2024-51539date:2025-02-25T14:15:31.153