SonicWall SMA100 Series Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in the SonicWall SMA100 series web interface, specifically in versions 10.2.1.15-81sv and earlier. This vulnerability allows remote, unauthenticated attackers to execute arbitrary JavaScript code.
Impact
Exploitation of this vulnerability could lead to reflected cross-site scripting, allowing for the execution of malicious JavaScript in the context of the user's browser.
Remediation
Users are advised to upgrade to SonicWall SMA100 series versions 10.2.2.1-90sv or higher. Additionally, enabling multifactor authentication and Web Application Firewall (WAF) on SMA100 can provide extra layers of security.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
