PT-2007-6622 · Sonicwall · Sonicwall Ssl-Vpn Netextender

Krafty

·

Published

2007-11-05

·

Updated

2018-10-15

·

CVE-2007-5603

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SonicWall SSL-VPN NetExtender versions prior to 2.1.0.51 SonicWall SSL-VPN NetExtender versions 2.5.x prior to 2.5.0.56
Description The issue is a stack-based buffer overflow in the NELaunchCtrl ActiveX control. This allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.
Recommendations For versions prior to 2.1.0.51, update to version 2.1.0.51 or later. For versions 2.5.x prior to 2.5.0.56, update to version 2.5.0.56 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5603

Affected Products

Sonicwall Ssl-Vpn Netextender