CVE-2013-1359

CRITICAL

DELL SonicWALL Analyzer 7.0, GMS 4.1-7.0, UMA 5.1-7.0, ViewPoint 4.1-6.0 - Authentication Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2013-1359. PoCs published by Metasploit, Nikolas Sotiriu, including Metasploit module exploits/multi/http/sonicwall_gms_upload.

AI-analyzed exploit summary This Metasploit module exploits an authentication bypass and arbitrary file upload vulnerability in SonicWALL GMS 6.0 to achieve remote code execution. It uploads a malicious JSP file that decodes and executes a payload, targeting both Windows and Linux platforms.

Description

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/24322

This Metasploit module exploits an authentication bypass and arbitrary file upload vulnerability in SonicWALL GMS 6.0 to achieve remote code execution. It uploads a malicious JSP file that decodes and executes a payload, targeting both Windows and Linux platforms.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SonicWALL GMS 6.0 (including 6.0.6017 and 6.0.6022)
No auth needed
Prerequisites: Network access to the SonicWALL GMS web interface · Target must be running a vulnerable version of SonicWALL GMS
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Nikolas Sotiriu · perlwebappsmultiple
https://www.exploit-db.com/exploits/24204

This exploit targets a vulnerability in SonicWALL GMS/VIEWPOINT 6.x and Analyzer 7.x, allowing remote code execution by uploading a malicious JSP shell. The exploit checks for vulnerability, determines the target OS, and uploads a reverse shell payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SonicWALL GMS/VIEWPOINT 6.x, Analyzer 7.x
No auth needed
Prerequisites: Network access to the target · Perl environment with required modules
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Nikolas Sotiriu · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/sonicwall_gms_upload.rb

This Metasploit module exploits an authentication bypass and arbitrary file upload vulnerability in SonicWALL GMS 6.0 to achieve remote code execution. It uploads a malicious JSP file to deploy a payload (WAR or executable) and trigger execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SonicWALL GMS 6.0 (including Virtual Appliance)
No auth needed
Prerequisites: Network access to SonicWALL GMS web interface · Vulnerable version of SonicWALL GMS (6.0)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/57445
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://www.exploit-db.com/exploits/24204
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://www.exploit-db.com/exploits/24322
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securitytracker.com/id/1028007
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/81367
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/author/7547/
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/fulldisclosure/2013/Jan/125

Scores

CVSS v3 9.8
EPSS 0.8947
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (12)
sonicwall/analyzer 7.0
sonicwall/global_management_system 4.1
sonicwall/global_management_system 5.0
sonicwall/global_management_system 5.1
sonicwall/global_management_system 6.0
sonicwall/global_management_system 7.0
sonicwall/universal_management_appliance 5.1
sonicwall/universal_management_appliance 6.0
sonicwall/universal_management_appliance 7.0
sonicwall/viewpoint 4.1
... and 2 more
Published Feb 11, 2020
Tracked Since Feb 18, 2026