PT-2024-9236 · Sonicwall · Sonicwall Sma100 Sslvpn

Alain Mowat

·

Published

2024-12-03

·

Updated

2024-12-06

·

CVE-2024-40763

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SonicWall SMA100 SSLVPN versions prior to 10.2.1.13-72sv
Description: The issue is related to a heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN, caused by the use of strcpy. This allows remote authenticated attackers to cause a heap-based buffer overflow, potentially leading to code execution. The vulnerability can be exploited by remote attackers, allowing them to execute arbitrary code.
Recommendations: For SonicWall SMA100 SSLVPN versions prior to 10.2.1.13-72sv, upgrade the affected components immediately to mitigate the risk. As a temporary workaround, consider restricting access to the vulnerable strcpy function until a patch is available.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-10924
CVE-2024-40763

Affected Products

Sonicwall Sma100 Sslvpn