Authentication Bypass Vulnerability in DELL SonicWALL Products
CVE-2013-1359
Key Information:
- Vendor
Sonicwall
- Vendor
- CVE Published:
- 11 February 2020
Badges
What is CVE-2013-1359?
An authentication bypass vulnerability allows remote attackers to gain unauthorized access to the root account of various DELL SonicWALL products, including the Analyzer and Global Management Systems, through manipulation of the skipSessionCheck parameter in the UMA interface. This flaw could enable threat actors to execute actions without proper authentication, posing significant risks to the security of device configurations and sensitive data management.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
89% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved