CVE-2020-5147

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
09/01/2021
Last modified:
21/09/2021

Description

SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:* 10.2.300 (including)