Remote Command Injection Vulnerability in SonicWall Secure Remote Access Server
CVE-2016-9683
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 22 February 2017
What is CVE-2016-9683?
The SonicWall Secure Remote Access server is susceptible to a Remote Command Injection vulnerability through its web administration interface. This flaw lies within the 'extensionsettings' CGI component, which inadequately sanitizes input from a certain multi-part form submission related to server configurations. The vulnerability allows an attacker to pass harmful commands via the 'scriptname' variable, leading to unauthorized shell access to the affected server under the 'nobody' user account. Prompt action is needed to mitigate risks associated with this security issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved