PT-2018-16861 · Sonicwall · Sonicos
Benjamin K.M
·
Published
2018-01-08
·
Updated
2024-06-15
·
CVE-2018-5280
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices
Description
The issue is related to a Cross-Site Scripting (XSS) vulnerability, which occurs via the Configure SSO screens. This allows for potential malicious script execution.
Recommendations
For SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices, consider disabling access to the Configure SSO screens as a temporary workaround until a fix is available. Restricting user input in these screens can also help minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonicos