PT-2007-6778 · Sonicwall · Sonicwall Ssl-Vpn Netextender

Bernhard Mueller

+1

·

Published

2007-11-05

·

Updated

2018-10-15

·

CVE-2007-5814

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SonicWall SSL-VPN NetExtender versions prior to 2.1.0.51 SonicWall SSL-VPN NetExtender versions 2.5.x prior to 2.5.0.56
Description The issue allows remote attackers to execute arbitrary code via a long Unicode property value in several parameters, including serverAddress, sessionId, clientIPLower, clientIPHigher, userName, domainName, or dnsSuffix.
Recommendations For versions prior to 2.1.0.51, update to version 2.1.0.51 or later. For versions 2.5.x prior to 2.5.0.56, update to version 2.5.0.56 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5814

Affected Products

Sonicwall Ssl-Vpn Netextender