CVE-2016-2396

CRITICAL

Dell SonicWALL GMS/Analyzer/UMA EM5000 7.2/8.0/8.1 - Authenticated RCE via GMS ViewPoint

Title source: llm
STIX 2.1

Description

The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to configuration input.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035015
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-16-164

Scores

CVSS v3 9.9
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (9)
sonicwall/analyzer 7.2
sonicwall/analyzer 8.0
sonicwall/analyzer 8.1
sonicwall/global_management_system 7.2
sonicwall/global_management_system 8.0
sonicwall/global_management_system 8.1
sonicwall/uma_em5000_firmware 7.2
sonicwall/uma_em5000_firmware 8.0
sonicwall/uma_em5000_firmware 8.1
Published Feb 17, 2016
Tracked Since Feb 18, 2026