Vulnerability Name: | CVE-2014-8420 (CCN-98911) | ||||||||
Assigned: | 2014-11-21 | ||||||||
Published: | 2014-11-21 | ||||||||
Updated: | 2018-03-12 | ||||||||
Summary: | The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-8420 Source: BID Type: Third Party Advisory, VDB Entry 71241 Source: CCN Type: BID-71241 Multiple Dell SonicWALL Products CVE-2014-8420 Multiple Remote Code Execution Vulnerabilities Source: CCN Type: DELL Web site Global Management System (GMS) Source: MISC Type: Third Party Advisory, VDB Entry http://www.zerodayinitiative.com/advisories/ZDI-14-385/ Source: XF Type: UNKNOWN dell-sonicwall-cve20148420-code-exec(98911) Source: XF Type: VDB Entry dell-sonicwall-cve20148420-code-exec(98911) Source: CONFIRM Type: Vendor Advisory https://support.software.dell.com/product-notification/136814 Source: CCN Type: ZDI-14-385 Dell Sonicwall GMS Virtual Appliance Multiple Remote Code Execution Vulnerabilities | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||
BACK |