CVE-2018-9866

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
03/08/2018
Last modified:
05/05/2025

Description

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:* 8.1 (including)