vendor:
SonicWALL Secure Remote Access (SRA) Appliance
by:
Veit Hailperin
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: SonicWALL Secure Remote Access (SRA) Appliance
Affected Version From: Dell SonicWALL SRA 7.5 prior to 7.5.1.0-38sv and 8.0 prior to 8.0.0.1-16sv
Affected Version To: Dell SonicWALL SRA 7.5.1.0-38sv and 8.0.0.1-16sv
Patch Exists: YES
Related CWE: CVE-2015-2248
CPE: a:dell:sonicwall_sra:7.5
Platforms Tested:
2015
Dell SonicWALL Secure Remote Access (SRA) Appliance Cross-Site Request Forgery
Use CSRF to force currently logged in user to create a bookmark pointing to an endpoint controlled by the attacker. Use subsequent request to call the bookmark just created. The identifier of the bookmark can be bruteforced using a single decrementing integer and causes minimal time delay. Gather the credentials on the target server provided in step #1
Mitigation:
Implement strong CSRF protection mechanisms, such as unique tokens for each request or the use of anti-CSRF libraries. Regularly update the Dell SonicWALL SRA appliance to the latest version.