Format String Vulnerabilities in SonicWALL Global VPN Client
CVE-2007-6273

Currently unrated

Key Information:

Vendor

Sonicwall

Vendor
CVE Published:
7 December 2007

What is CVE-2007-6273?

Multiple format string vulnerabilities exist in the configuration files of SonicWALL Global VPN Client versions 3.1.556 and 4.0.0.810. These vulnerabilities allow user-assisted remote attackers to exploit format string specifiers in the Hostname tag or name attribute of the Connection tag, potentially leading to arbitrary code execution. This issue does not appear to cross privilege boundaries, but its exploitation could allow unauthorized code execution under certain conditions.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.