Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in the (1) Hostname tag or the (2) name attribute in the Connection tag. NOTE: there might not be any realistic circumstances in which this issue crosses privilege boundaries.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SonicWALL Global VPN客户端远程格式串处理漏洞
Vulnerability Description
SonicWALL Global VPN客户端允许移动用户建立到SonicWALL VPN网关的安全连接,访问关键网络资源。 SonicWALL Global VPN客户端处理配置文件时存在格式串漏洞,本地攻击者可能利用此漏洞提升权限。 如果攻击者提供了特制的配置文件,则客户端解析配置文件中Connection标签的name属性和Hostname标签的内容时,就会触发格式串漏洞,导致读写进程内存空间中的任意内存地址。
CVSS Information
N/A
Vulnerability Type
N/A