PT-2024-22669 · Sonicwall · Gms
Published
2024-04-30
·
Updated
2024-05-07
·
CVE-2024-29010
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GMS versions 9.3.4 and earlier
Description
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue could allow remote attackers to disclose sensitive information on affected installations of SonicWALL GMS Virtual Appliance, although authentication is required to exploit this vulnerability.
Recommendations
For GMS versions 9.3.4 and earlier, consider disabling the XML external entity processing in the GMS ECM URL endpoint as a temporary workaround until a patch is available. Restrict access to the GMS ECM URL endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gms