Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-5280


SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.


Published

2018-01-08T09:29:00.243

Last Modified

2024-11-21T04:08:29.770

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sonicwall sonicos 6.2.7.0 Yes
Operating System sonicwall sonicos 6.2.9.0 Yes
Operating System sonicwall sonicos 6.5.0.0 Yes
Operating System sonicwall sonicos 6.5.1.0 Yes
Operating System sonicwall sonicos 6.5.2.0 Yes
Hardware sonicwall nsa_250m - No
Hardware sonicwall nsa_2600 - No
Hardware sonicwall nsa_2650 - No
Hardware sonicwall nsa_3600 - No
Hardware sonicwall nsa_4600 - No
Hardware sonicwall nsa_5600 - No
Hardware sonicwall nsa_6600 - No

References