SonicOS
cpe:2.3:a:sonicwall:sonicosv:*:*:*:*:*:*:*, +7 more
- <= 6.5.5.1-6n
- <= 7.0.1-5169
- <= 7.3.1-7013
- <= 8.1.0-8017
A post-authentication path traversal vulnerability exists in SonicWall SonicOS, allowing attackers to access and interact with typically restricted services. This vulnerability affects several generations of SonicWall firewalls and NSv platforms, with specific version ranges vulnerable.
Exploitation of this vulnerability could lead to unauthorized access to restricted services, potentially allowing for further exploitation or manipulation of the device or network.
Administrators are advised to disable HTTP or HTTPS-based firewall management and SSL-VPN access on all interfaces, restricting management access to SSH only. Once the vulnerability has been addressed, SonicWall PSIRT recommends consulting the official SonicWall support channels for guidance on re-enabling management access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.