Unquoted Service Path Vulnerability in SonicWall NetExtender Windows Client
CVE-2020-5147

5.3MEDIUM

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
9 January 2021

Summary

The SonicWall NetExtender Windows client is affected by an unquoted service path vulnerability, which allows local attackers to execute code with elevated privileges on the host operating system. This flaw impacts versions 10.2.300 and earlier, potentially enabling unauthorized access and manipulation of critical system functions. Users are advised to follow the recommended patches and updates to mitigate the risk associated with this vulnerability.

Affected Version(s)

SonicWall NetExtender 10.2.300 and earlier

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.