Skip to main content

SonicWALL Products Two Security Bypass Vulnerabilities

Last Update Date: 21 Jan 2013 15:24 Release Date: 21 Jan 2013 3839 Views

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

Multiple vulnerabilities have been identified in various SonicWALL products, which can be exploited by malicious people to bypass certain security restrictions.

  1. An error when handling request for changing users password can be exploited to change the administrator's password.
  2. An error within the authentication mechanism in the web interface can be exploited to bypass the authentication mechanism by setting the "skipSessionCheck" parameter to "1".

Impact

  • Security Restriction Bypass

System / Technologies affected

  • SonicWALL Analyzer 7.x
  • SonicWALL Global Management System 4.x
  • SonicWALL Global Management System 5.x
  • SonicWALL Global Management System 6.x
  • SonicWALL Global Management System 7.x
  • SonicWALL UMA EM5000 5.x
  • SonicWALL UMA EM5000 6.x
  • SonicWALL UMA EM5000 7.x
  • SonicWALL ViewPoint 4.x
  • SonicWALL ViewPoint 5.x
  • SonicWALL ViewPoint 6.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply Hotfix 125076.77

Vulnerability Identifier


Source


Related Link