6.8

CVE-2026-0205

Medienbericht
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SonicwallSonicos Version < 6.5.5.2-28n
   SonicwallNsa 2650 Version-
   SonicwallNsa 3600 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 4600 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 5600 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6600 Version-
   SonicwallNsa 6650 Version-
   SonicwallSm 9200 Version-
   SonicwallSm 9250 Version-
   SonicwallSm 9400 Version-
   SonicwallSm 9450 Version-
   SonicwallSm 9600 Version-
   SonicwallSm 9650 Version-
   SonicwallSoho 250 Version-
   SonicwallSoho 250w Version-
   SonicwallSohow Version-
   SonicwallTz 300 Version-
   SonicwallTz 300p Version-
   SonicwallTz 300w Version-
   SonicwallTz 350 Version-
   SonicwallTz 350w Version-
   SonicwallTz 400 Version-
   SonicwallTz 400w Version-
   SonicwallTz 500 Version-
   SonicwallTz 500w Version-
   SonicwallTz 600 Version-
   SonicwallTz 600p Version-
SonicwallSonicos Version >= 7.0.0.0 <= 7.0.1-5169
   SonicwallNsa 2700 Version-
   SonicwallNsa 3700 Version-
   SonicwallNsa 4700 Version-
   SonicwallNsa 5700 Version-
   SonicwallNsa 6700 Version-
   SonicwallNssp 10700 Version-
   SonicwallNssp 11700 Version-
   SonicwallNssp 13700 Version-
   SonicwallNssp 15700 Version-
   SonicwallNsv 270 Version-
   SonicwallNsv 470 Version-
   SonicwallNsv 870 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz670 Version-
SonicwallSonicos Version >= 7.1.1-7040 < 7.3.2-7010
   SonicwallNsa 2700 Version-
   SonicwallNsa 3700 Version-
   SonicwallNsa 4700 Version-
   SonicwallNsa 5700 Version-
   SonicwallNsa 6700 Version-
   SonicwallNssp 10700 Version-
   SonicwallNssp 11700 Version-
   SonicwallNssp 13700 Version-
   SonicwallNssp 15700 Version-
   SonicwallNsv 270 Version-
   SonicwallNsv 470 Version-
   SonicwallNsv 870 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz670 Version-
SonicwallSonicos Version >= 8.0.0-8035 < 8.2.0-8009
   SonicwallNsa 2800 Version-
   SonicwallNsa 3800 Version-
   SonicwallNsa 4800 Version-
   SonicwallNsa 5800 Version-
   SonicwallTz280 Version-
   SonicwallTz280w Version-
   SonicwallTz380 Version-
   SonicwallTz380w Version-
   SonicwallTz480 Version-
   SonicwallTz580 Version-
   SonicwallTz680 Version-
   SonicwallTz80 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.8 2.1 4.7
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
CWE-35 Path Traversal: '.../...//'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.