PT-2016-2697 · Dell · Dell Sonicwall Uma Em5000+2

Cpnrodzc7

·

Published

2016-02-10

·

Updated

2018-03-12

·

CVE-2016-2397

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056 Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056 Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056
Description The issue is related to the cliserver implementation, which lacks input data sanitization measures. This allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. The vulnerability can be exploited by sending specially formed XML data, enabling the execution of arbitrary Java code.
Recommendations For Dell SonicWALL GMS versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue. For Dell SonicWALL Analyzer versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue. For Dell SonicWALL UMA EM5000 versions 7.2 through 8.1 before Hotfix 168056, apply Hotfix 168056 to resolve the issue. As a temporary workaround, consider restricting access to the cliserver implementation until the hotfix is applied.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02089
CVE-2016-2397
ZDI-16-163

Affected Products

Dell Sonicwall Analyzer
Dell Sonicwall Gms
Dell Sonicwall Uma Em5000