CVE-2018-5280

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/01/2018
Last modified:
16/06/2022

Description

SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:sonicos:6.2.7.0:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sonicos:6.2.9.0:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sonicos:6.5.0.0:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sonicos:6.5.1.0:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sonicos:6.5.2.0:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_250m:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_2600:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_2650:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_3600:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_4600:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_5600:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_6600:-:*:*:*:*:*:*:*