The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.
2016-02-17T15:59:07.690
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sonicwall | uma_em5000_firmware | 7.2 | Yes |
Operating System | sonicwall | uma_em5000_firmware | 8.0 | Yes |
Operating System | sonicwall | uma_em5000_firmware | 8.1 | Yes |
Hardware | sonicwall | uma_em5000 | - | No |
Application | sonicwall | analyzer | 7.2 | Yes |
Application | sonicwall | analyzer | 8.0 | Yes |
Application | sonicwall | analyzer | 8.1 | Yes |
Application | sonicwall | global_management_system | 7.2 | Yes |
Application | sonicwall | global_management_system | 8.0 | Yes |
Application | sonicwall | global_management_system | 8.1 | Yes |