Dell Secure Connect Gateway-Appliance vulnerabilities
9 known vulnerabilities affecting dell/secure_connect_gateway-appliance.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2024-29168P3HIGHCVSS 8.8≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-29168 [HIGH] CWE-89 CVE-2024-29168: Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an i
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of applic
nvd
CVE-2024-29169P3HIGHCVSS 8.1≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-29169 [HIGH] CWE-89 CVE-2024-29169: Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an i
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of applica
nvd
CVE-2023-44294P3MEDIUMCVSS 6.5≥ v5.10.00.00, ≤ v5.18.00.002024-02-14
CVE-2023-44294 [MEDIUM] CWE-89 CVE-2023-44294: In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.0
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API.
This issue may potentially lead to unintentional information disclosure from the
nvd
CVE-2023-44293P3MEDIUMCVSS 6.5≥ v5.10.00.00, ≤ v5.18.00.002024-02-14
CVE-2023-44293 [MEDIUM] CWE-89 CVE-2023-44293: In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.0
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the pr
nvd
CVE-2024-28968P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28968 [MEDIUM] CWE-284 CVE-2024-28968: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on
nvd
CVE-2024-28965P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28965 [MEDIUM] CWE-284 CVE-2024-28965: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain Internal APIs applicable only for Admin Users on the applicat
nvd
CVE-2024-28966P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28966 [MEDIUM] CWE-284 CVE-2024-28966: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's bac
nvd
CVE-2024-28967P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28967 [MEDIUM] CWE-284 CVE-2024-28967: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application'
nvd
CVE-2024-28969P4MEDIUMCVSS 4.3≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28969 [MEDIUM] CWE-284 CVE-2024-28969: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's bac
nvd