CVE-2018-9866
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
03/08/2018
Last modified:
05/05/2025
Description
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:* | 8.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/rapid7/metasploit-framework/pull/10305
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007
- https://twitter.com/ddouhine/status/1019251292202586112
- https://github.com/rapid7/metasploit-framework/pull/10305
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007
- https://twitter.com/ddouhine/status/1019251292202586112



