CVE-2013-1359
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 89.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 89.40% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sonicwall/analyzer · sonicwall/global management system · sonicwall/universal management appliance · sonicwall/viewpoint
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/24204Exploit, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/24322Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/57445Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1028007Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81367Third Party Advisory, VDB Entry
- https://fortiguard.com/encyclopedia/ips/35264/multiple-sonicwall-products-authentication-bypass-vulnsThird Party Advisory
- https://packetstormsecurity.com/files/author/7547/Exploit, Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2013/Jan/125Exploit, Mailing List, Third Party Advisory
- http://www.exploit-db.com/exploits/24204Exploit, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/24322Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/57445Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1028007Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81367Third Party Advisory, VDB Entry
- https://fortiguard.com/encyclopedia/ips/35264/multiple-sonicwall-products-authentication-bypass-vulnsThird Party Advisory
- https://packetstormsecurity.com/files/author/7547/Exploit, Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2013/Jan/125Exploit, Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.