10
CVE-2013-1360
- EPSS 23.21%
- Veröffentlicht 11.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 01:49:25
- Erkennungen
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Global Management System Version 4.1
Sonicwall ≫ Global Management System Version 5.0
Sonicwall ≫ Global Management System Version 5.1
Sonicwall ≫ Global Management System Version 6.0
Sonicwall ≫ Global Management System Version 7.0
Sonicwall ≫ Universal Management Appliance Version 5.1
Sonicwall ≫ Universal Management Appliance Version 6.0
Sonicwall ≫ Universal Management Appliance Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 23.21% | 0.975 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.html
http://www.exploit-db.com/exploits/24203
http://www.securityfocus.com/bid/57446
http://www.securitytracker.com/id/1028007
https://exchange.xforce.ibmcloud.com/vulnerabilities/81366
https://packetstormsecurity.com/files/cve/CVE-2013-1360