PT-2016-2697 · Dell · Dell Sonicwall Uma Em5000+2
Cpnrodzc7
·
Published
2016-02-10
·
Updated
2018-03-12
·
CVE-2016-2397
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056
Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056
Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056
Description
The issue is related to the cliserver implementation, which lacks input data sanitization measures. This allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. The vulnerability can be exploited by sending specially formed XML data, enabling the execution of arbitrary Java code.
Recommendations
For Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue.
For Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue.
For Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue.
As a temporary workaround, consider restricting access to the cliserver implementation until the hotfix is applied.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Sonicwall Analyzer
Dell Sonicwall Gms
Dell Sonicwall Uma Em5000