ZeroHour

CVE-2018-9866

PoC
CVSS 3.1
9.8 critical
EPSS
5%p91
Published
()
Modified
Description

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

Vendors
sonicwall
Products
global management system
Weakness
CWE-77, CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news