CVE-2015-4173

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*
cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*

History

21 Nov 2024, 02:30

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/133302/Dell-SonicWall-NetExtender-7.5.215-Privilege-Escalation.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/133302/Dell-SonicWall-NetExtender-7.5.215-Privilege-Escalation.html - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/536303/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/536303/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1033417 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1033417 - Third Party Advisory, VDB Entry
References () https://support.software.dell.com/product-notification/157537 - Broken Link () https://support.software.dell.com/product-notification/157537 - Broken Link

Information

Published : 2015-08-26 19:59

Updated : 2024-11-21 02:30


NVD link : CVE-2015-4173

Mitre link : CVE-2015-4173

CVE.ORG link : CVE-2015-4173


JSON object : View

Products Affected

sonicwall

  • netextender
CWE
CWE-428

Unquoted Search Path or Element