PT-2018-15290 · Sonicwall · Secure Access Sa Series Ssl Vpn

Rafael Pedrero

·

Published

2018-12-21

·

Updated

2019-10-03

·

CVE-2018-20193

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Secure Access SA Series SSL VPN versions 4.2 through 5.1R5
Description The issue allows for privilege escalation. This is demonstrated by the ability of a readonly user to change the administrator user password. The exploitation occurs because appropriate controls are not performed, allowing a readonly user to make a local copy of the /dana-admin/user/update.cgi page, change the user value, and save the changes.
Recommendations For Secure Access SA Series SSL VPN versions 4.2 through 5.1R5, consider restricting access to the /dana-admin/user/update.cgi page to prevent unauthorized changes to the administrator user password. As a temporary workaround, restrict the ability of readonly users to modify the user value in the update.cgi page until a patch is available.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20193

Affected Products

Secure Access Sa Series Ssl Vpn