Showing 3 vulnerabilities on this page for global_management_system

Signals CISA KEV Ransomware Nuclei
SonicWall vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.

CWE-259May 1, 2024
CVSS7.5v3.1EPSS0.884%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.

CWE-611May 1, 2024
CVSS7.1v3.1EPSS0.621%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall global_management_system Improper Neutralization of Special Elements used in a Command ('Command Injection')

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

CWE-20CWE-77Aug 3, 2018
CVSS9.8v3.1EPSS4.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX