PT-2020-7344 · Dell · Sonicwall Global Management System+3
Nikolas Sotiriu
·
Published
2020-02-11
·
Updated
2020-02-14
·
CVE-2013-1359
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
DELL SonicWALL Analyzer version 7.0
DELL SonicWALL Global Management System (GMS) versions 4.1 through 7.0
DELL SonicWALL Universal Management Appliance (UMA) versions 5.1 through 7.0
DELL SonicWALL ViewPoint versions 4.1 through 6.0
Description:
An Authentication Bypass issue exists, allowing a remote malicious user to obtain access to the root account via the
skipSessionCheck parameter to the "/appliance/" interface.Recommendations:
For DELL SonicWALL Analyzer version 7.0, avoid using the
skipSessionCheck parameter in the "/appliance/" interface until the issue is resolved.
For DELL SonicWALL Global Management System (GMS) versions 4.1 through 7.0, restrict access to the UMA interface to minimize the risk of exploitation.
For DELL SonicWALL Universal Management Appliance (UMA) versions 5.1 through 7.0, consider disabling the /appliance/ interface until a patch is available.
For DELL SonicWALL ViewPoint versions 4.1 through 6.0, restrict access to the /appliance/ interface to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonicwall Analyzer
Sonicwall Global Management System
Sonicwall Universal Management Appliance
Sonicwall Viewpoint