Insecure Library Loading Vulnerability in SonicWall Global VPN Client
CVE-2020-5145

8.6HIGH

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
28 October 2020

Summary

The SonicWall Global VPN Client versions up to 4.10.4.0314 are susceptible to an insecure library loading vulnerability. This can be exploited through DLL hijacking, allowing an attacker to execute arbitrary code remotely on the target system. Users of affected versions should take immediate action to secure their systems and apply available updates to mitigate this risk.

Affected Version(s)

SonicWall Global VPN Client 4.10.4.0314 and earlier

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.