Описание
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken Link
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 7.5.227 (исключая)Версия от 8.0 (включая) до 8.0.238 (исключая)
Одно из
cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*
cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*
EPSS
Процентиль: 56%
0.00338
Низкий
6.9 Medium
CVSS2
Дефекты
CWE-428
Связанные уязвимости
github
больше 3 лет назад
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
EPSS
Процентиль: 56%
0.00338
Низкий
6.9 Medium
CVSS2
Дефекты
CWE-428