CVE-2016-9684 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn't properly escape the information it's passed in the 'CERT' variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.06% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-02-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| dell | sonicwall secure remote access server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sonicwall 8.1.0.2-14sv - 'viewcert.cgi' Remote Command Injection (Metasploit) | 2016-12-24 |
References
- http://documents.software.dell.com/sonicwall-sma-100-series/8.1.0.7/release-notes/resolved-issues?ParentProduct=868
- http://pastebin.com/g1e2qU6N
- http://www.securityfocus.com/bid/96375
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2016-0005
- http://documents.software.dell.com/sonicwall-sma-100-series/8.1.0.7/release-notes/resolved-issues?ParentProduct=868
- http://pastebin.com/g1e2qU6N
- http://www.securityfocus.com/bid/96375
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2016-0005
→ the Explorer · watch your stack · NVD