CVE-2024-45315

MEDIUM

SonicWall Connect Tunnel <12.4.3.271 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 9.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-59
Status published
Products (1)
SonicWall/Connect Tunnel 12.4.3.271 and earlier versions
Published Oct 11, 2024
Tracked Since Feb 18, 2026