PT-2018-15290 · Sonicwall · Secure Access Sa Series Ssl Vpn
Rafael Pedrero
·
Published
2018-12-21
·
Updated
2019-10-03
·
CVE-2018-20193
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Secure Access SA Series SSL VPN versions 4.2 through 5.1R5
Description
The issue allows for privilege escalation. This is demonstrated by the ability of a readonly user to change the administrator user password. The exploitation occurs because appropriate controls are not performed, allowing a readonly user to make a local copy of the /dana-admin/user/update.cgi page, change the
user value, and save the changes.Recommendations
For Secure Access SA Series SSL VPN versions 4.2 through 5.1R5, consider restricting access to the /dana-admin/user/update.cgi page to prevent unauthorized changes to the administrator user password. As a temporary workaround, restrict the ability of readonly users to modify the
user value in the update.cgi page until a patch is available.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secure Access Sa Series Ssl Vpn