vendor:
NetExtender
by:
shinnai
5,3
CVSS
MEDIUM
Unquoted Service Path
426
CWE
Product Name: NetExtender
Affected Version From: 10.2.0.300
Affected Version To: 10.2.0.300
Patch Exists: Yes
Related CWE: CVE-2020-5147
CPE: a:sonicwall:netextender:10.2.0.300
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=155351, https://www.infosecmatter.com/nessus-plugin-library/?id=141100, https://www.infosecmatter.com/nessus-plugin-library/?id=101974, https://www.infosecmatter.com/nessus-plugin-library/?id=127480, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/sixapart_movabletype_storable_exec
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
SonicWall NetExtender windows client unquoted service path vulnerability
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.
Mitigation:
Update to the latest version of SonicWall NetExtender Windows client.