Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.806043
Kategorie:Privilege escalation
Titel:Dell SonicWall NetExtender Privilege Escalation Vulnerability - Windows
Zusammenfassung:Dell SonicWall NetExtender is prone to a privilege escalation vulnerability.;; This VT has been deprecated and replaced by the VT 'Dell SonicWall NetExtender < 7.5.227, 8.x < 8.0.238 Privilege; Escalation Vulnerability - Windows' (OID: 1.3.6.1.4.1.25623.1.0.170896).
Beschreibung:Summary:
Dell SonicWall NetExtender is prone to a privilege escalation vulnerability.

This VT has been deprecated and replaced by the VT 'Dell SonicWall NetExtender < 7.5.227, 8.x < 8.0.238 Privilege
Escalation Vulnerability - Windows' (OID: 1.3.6.1.4.1.25623.1.0.170896).

Vulnerability Insight:
The flaw exists due to Unquoted Windows
search path vulnerability in the autorun value upon installation of the product.

Vulnerability Impact:
Successful exploitation will allow attacker
privileged code execution upon administrative login.

Affected Software/OS:
Dell SonicWall NetExtender version before
7.5.227 and before 8.0.238 on Windows.

Solution:
Upgrade to firmware version 7.5.227 or 8.0.238 or later.

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-4173
Bugtraq: 20150824 Dell SonicWall NetExtender Unquoted Autorun Privilege Escalation (Google Search)
http://www.securityfocus.com/archive/1/536303/100/0/threaded
http://packetstormsecurity.com/files/133302/Dell-SonicWall-NetExtender-7.5.215-Privilege-Escalation.html
http://www.securitytracker.com/id/1033417
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.