CVE-2013-1360
CRITICALSonicWall GMS Analyzer UMA ViewPoint - Authentication Bypass via SGMS Interface
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-1360. PoCs published by Nikolas Sotiriu.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in SonicWALL GMS/Viewpoint/Analyzer by crafting a malicious URL that leverages broken session handling during the password change process. The attacker gains full administrative access without valid credentials.
Description
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in SonicWALL GMS/Viewpoint/Analyzer by crafting a malicious URL that leverages broken session handling during the password change process. The attacker gains full administrative access without valid credentials.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H