Description
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- SonicWall / SonicOS6.5.4.15-117n and older versions – 6.5.4.15-117n and older versions
- SonicWall / SonicOS7.0.1-5161 and older versions – 7.0.1-5161 and older versions
- SonicWall / SonicOS7.1.1-7058 and older versions – 7.1.1-7058 and older versions
- SonicWall / SonicOS7.1.2-7019 – 7.1.2-7019
- SonicWall / SonicOS8.0.0-8035 – 8.0.0-8035