CVE-2013-1360
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 23.21% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sonicwall/analyzer · sonicwall/global management system · sonicwall/universal management appliance · sonicwall/viewpoint
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.htmlBroken Link
- http://www.exploit-db.com/exploits/24203Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/57446Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1028007Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81366Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/cve/CVE-2013-1360Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.htmlBroken Link
- http://www.exploit-db.com/exploits/24203Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/57446Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1028007Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81366Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/cve/CVE-2013-1360Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.