PT-2024-22669 · Sonicwall · Gms

Published

2024-04-30

·

Updated

2024-05-07

·

CVE-2024-29010

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions GMS versions 9.3.4 and earlier
Description The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue could allow remote attackers to disclose sensitive information on affected installations of SonicWALL GMS Virtual Appliance, although authentication is required to exploit this vulnerability.
Recommendations For GMS versions 9.3.4 and earlier, consider disabling the XML external entity processing in the GMS ECM URL endpoint as a temporary workaround until a patch is available. Restrict access to the GMS ECM URL endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-29010
ZDI-24-420

Affected Products

Gms