Описание
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.5.3.3 (включая)
cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:a:sonicwall:sonicos_sslvpn_nacagent:3.5:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 11%
0.00038
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-428
CWE-428
Связанные уязвимости
github
больше 3 лет назад
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
EPSS
Процентиль: 11%
0.00038
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-428
CWE-428