PT-2018-16861 · Sonicwall · Sonicos

Benjamin K.M

·

Published

2018-01-08

·

Updated

2024-06-15

·

CVE-2018-5280

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices
Description The issue is related to a Cross-Site Scripting (XSS) vulnerability, which occurs via the Configure SSO screens. This allows for potential malicious script execution.
Recommendations For SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices, consider disabling access to the Configure SSO screens as a temporary workaround until a fix is available. Restricting user input in these screens can also help minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5280
OPENSUSE-SU-2024:11290-1

Affected Products

Sonicos