PT-2016-2697 · Dell · Dell Sonicwall Uma Em5000+2

Cpnrodzc7

·

Publicado

2016-02-10

·

Atualizado

2018-03-12

·

CVE-2016-2397

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056 Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056 Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056
Description The issue is related to the cliserver implementation, which lacks input data sanitization measures. This allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. The vulnerability can be exploited by sending specially formed XML data, enabling the execution of arbitrary Java code.
Recommendations For Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue. For Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue. For Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue. As a temporary workaround, consider restricting access to the cliserver implementation until the hotfix is applied.

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02089
CVE-2016-2397
ZDI-16-163

Produtos afetados

Dell Sonicwall Analyzer
Dell Sonicwall Gms
Dell Sonicwall Uma Em5000