CVE-2007-5814: Buffer Overflow
Multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote attackers to execute arbitrary code via a long (1) serverAddress, (2) sessionId, (3) clientIPLower, (4) clientIPHigher, (5) userName, (6) domainName, or (7) dnsSuffix Unicode property value. NOTE: the AddRouteEntry vector is covered by CVE-2007-5603.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5814?
CVE-2007-5814 is considered critical due to its potential for remote code execution.
How do I fix CVE-2007-5814?
To fix CVE-2007-5814, update the SonicWall SSL-VPN to version 2.1.0.51 or 2.5.0.56 or later.
Which SonicWall SSL-VPN versions are affected by CVE-2007-5814?
CVE-2007-5814 affects SonicWall SSL-VPN versions before 2.1.0.51 and 2.5.x versions before 2.5.0.56.
What vulnerabilities does CVE-2007-5814 exploit?
CVE-2007-5814 exploits multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control.
Can CVE-2007-5814 allow unauthorized access?
Yes, CVE-2007-5814 can enable remote attackers to execute arbitrary code, potentially leading to unauthorized system access.