PT-2020-7344 · Dell · Sonicwall Global Management System+3

Nikolas Sotiriu

·

Published

2020-02-11

·

Updated

2020-02-14

·

CVE-2013-1359

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: DELL SonicWALL Analyzer version 7.0 DELL SonicWALL Global Management System (GMS) versions 4.1 through 7.0 DELL SonicWALL Universal Management Appliance (UMA) versions 5.1 through 7.0 DELL SonicWALL ViewPoint versions 4.1 through 6.0
Description: An Authentication Bypass issue exists, allowing a remote malicious user to obtain access to the root account via the skipSessionCheck parameter to the "/appliance/" interface.
Recommendations: For DELL SonicWALL Analyzer version 7.0, avoid using the skipSessionCheck parameter in the "/appliance/" interface until the issue is resolved. For DELL SonicWALL Global Management System (GMS) versions 4.1 through 7.0, restrict access to the UMA interface to minimize the risk of exploitation. For DELL SonicWALL Universal Management Appliance (UMA) versions 5.1 through 7.0, consider disabling the /appliance/ interface until a patch is available. For DELL SonicWALL ViewPoint versions 4.1 through 6.0, restrict access to the /appliance/ interface to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1359

Affected Products

Sonicwall Analyzer
Sonicwall Global Management System
Sonicwall Universal Management Appliance
Sonicwall Viewpoint