6.5
CVE-2026-0516
- EPSS 0.21%
- Veröffentlicht 05.08.2026 11:50:03
- Zuletzt bearbeitet 05.08.2026 20:17:04
- CVE-Watchlists
- Unerledigt
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSonicWall
≫
Produkt
SonicOS
Default Statusunknown
Version
6.5.5.2-28n and older versions
Status
affected
Version
7.0.1-5169 and older versions
Status
affected
Version
7.3.3-7015 and older versions
Status
affected
Version
8.2.1-8010 and older versions
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.106 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0009