CVE-2013-1360

CRITICAL

SonicWall GMS Analyzer UMA ViewPoint - Authentication Bypass via SGMS Interface

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-1360. PoCs published by Nikolas Sotiriu.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in SonicWALL GMS/Viewpoint/Analyzer by crafting a malicious URL that leverages broken session handling during the password change process. The attacker gains full administrative access without valid credentials.

Description

An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.

Exploits (1)

exploitdb WORKING POC
by Nikolas Sotiriu · textwebappsmultiple
https://www.exploit-db.com/exploits/24203

This exploit demonstrates an authentication bypass vulnerability in SonicWALL GMS/Viewpoint/Analyzer by crafting a malicious URL that leverages broken session handling during the password change process. The attacker gains full administrative access without valid credentials.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SonicWALL GMS/Analyzer/ViewPoint versions 7.0.x, 6.0.x, 5.1.x, 5.0.x, 4.1.x
No auth needed
Prerequisites: Network access to the target system · Target system running vulnerable SonicWALL software
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securitytracker.com/id/1028007
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/57446
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/81366
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://www.exploit-db.com/exploits/24203
Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/cve/CVE-2013-1360

Scores

CVSS v3 9.8
EPSS 0.5772
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (12)
sonicwall/analyzer 7.0
sonicwall/global_management_system 4.1
sonicwall/global_management_system 5.0
sonicwall/global_management_system 5.1
sonicwall/global_management_system 6.0
sonicwall/global_management_system 7.0
sonicwall/universal_management_appliance 5.1
sonicwall/universal_management_appliance 6.0
sonicwall/universal_management_appliance 7.0
sonicwall/viewpoint 4.1
... and 2 more
Published Feb 11, 2020
Tracked Since Feb 18, 2026