CVE-2013-1360 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 23.2% (pctl 98)
Patch early
A public exploit exists.
Description
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 23.21% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-02-11 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| sonicwall | analyzer |
| sonicwall | global management system |
| sonicwall | universal management appliance |
| sonicwall | viewpoint |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SonicWALL GMS/Viewpoint/Analyzer - Authentication Bypass | 2013-01-18 |
References
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.html
- http://www.exploit-db.com/exploits/24203
- http://www.securityfocus.com/bid/57446
- http://www.securitytracker.com/id/1028007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81366
- https://packetstormsecurity.com/files/cve/CVE-2013-1360
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0075.html
- http://www.exploit-db.com/exploits/24203
- http://www.securityfocus.com/bid/57446
- http://www.securitytracker.com/id/1028007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81366
- https://packetstormsecurity.com/files/cve/CVE-2013-1360
→ the Explorer · watch your stack · NVD