CVE-2013-1360
critical · 9.8An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
9.8
CVSS
23.2%
EPSS (exploit prob.)
98th
EPSS percentile
2020-02-11
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sonicwall | analyzer | 7.0 |
| sonicwall | global_management_system | 4.1 |
| sonicwall | global_management_system | 5.0 |
| sonicwall | global_management_system | 5.1 |
| sonicwall | global_management_system | 6.0 |
| sonicwall | global_management_system | 7.0 |
| sonicwall | universal_management_appliance | 5.1 |
| sonicwall | universal_management_appliance | 6.0 |
| sonicwall | universal_management_appliance | 7.0 |
| sonicwall | viewpoint | 4.1 |
| sonicwall | viewpoint | 5.0 |
| sonicwall | viewpoint | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.html
- http://www.exploit-db.com/exploits/24203
- http://www.securityfocus.com/bid/57446
- http://www.securitytracker.com/id/1028007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81366
- https://packetstormsecurity.com/files/cve/CVE-2013-1360
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.html
- http://www.exploit-db.com/exploits/24203
- http://www.securityfocus.com/bid/57446
- http://www.securitytracker.com/id/1028007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81366
- https://packetstormsecurity.com/files/cve/CVE-2013-1360
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-1360