Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-1360


An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.


Published

2020-02-11T16:15:12.227

Last Modified

2024-11-21T01:49:25.667

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sonicwall analyzer 7.0 Yes
Application sonicwall global_management_system 4.1 Yes
Application sonicwall global_management_system 5.0 Yes
Application sonicwall global_management_system 5.1 Yes
Application sonicwall global_management_system 6.0 Yes
Application sonicwall global_management_system 7.0 Yes
Application sonicwall universal_management_appliance 5.1 Yes
Application sonicwall universal_management_appliance 6.0 Yes
Application sonicwall universal_management_appliance 7.0 Yes
Application sonicwall viewpoint 4.1 Yes
Application sonicwall viewpoint 5.0 Yes
Application sonicwall viewpoint 6.0 Yes

References