60
CVE-2018-9866
PoC —CVSS 3.1
9.8 critical
EPSS
5%p91
Published
()
Modified
Description
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.
- Vendors
- sonicwall
- Products
- global management system
- Weakness
- CWE-77, CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H