SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-4173

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via…

MEDIUM 6.9EPSS 2.07%

Does this matter?

Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.

Description

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

CVSS 2.0
6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
2.07% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-428
Affected
sonicwall/netextender
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.