PT-2016-2697 · Dell · Dell Sonicwall Uma Em5000+2
Cpnrodzc7
·
Publicado
2016-02-10
·
Atualizado
2018-03-12
·
CVE-2016-2397
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056
Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056
Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056
Description
The issue is related to the cliserver implementation, which lacks input data sanitization measures. This allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. The vulnerability can be exploited by sending specially formed XML data, enabling the execution of arbitrary Java code.
Recommendations
For Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue.
For Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue.
For Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue.
As a temporary workaround, consider restricting access to the cliserver implementation until the hotfix is applied.
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Sonicwall Analyzer
Dell Sonicwall Gms
Dell Sonicwall Uma Em5000