CVE-2015-2248
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for…
Does this matter?
Lower severity and a low EPSS score (3.93%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.93% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- sonicwall/remote access firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/131762/Dell-SonicWALL-Secure-Remote-Access-7.5-8.0-CSRF.htmlThird Party Advisory, VDB Entry
- http://www.scip.ch/en/?vuldb.75111Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/73098Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032227Third Party Advisory, VDB Entry
- https://support.software.dell.com/product-notification/151370?productName=SonicWALL%20SRA%20SeriesPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/36940/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/131762/Dell-SonicWALL-Secure-Remote-Access-7.5-8.0-CSRF.htmlThird Party Advisory, VDB Entry
- http://www.scip.ch/en/?vuldb.75111Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/73098Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032227Third Party Advisory, VDB Entry
- https://support.software.dell.com/product-notification/151370?productName=SonicWALL%20SRA%20SeriesPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/36940/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.