CVE-2016-2396: Command Injection
The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to configuration input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2396?
CVE-2016-2396 is considered a high severity vulnerability that allows remote authenticated users to execute arbitrary commands.
How do I fix CVE-2016-2396?
To fix CVE-2016-2396, update your Dell SonicWALL GMS, Analyzer, or UMA EM5000 to the patched versions above Hotfix 168056.
Who is affected by CVE-2016-2396?
CVE-2016-2396 affects users running Dell SonicWALL GMS, Analyzer, and UMA EM5000 versions 7.2, 8.0, and 8.1 before Hotfix 168056.
What can attackers do with CVE-2016-2396?
Attackers exploiting CVE-2016-2396 can execute arbitrary commands on the affected systems, which could lead to further system compromise.
Is CVE-2016-2396 exploitable remotely?
Yes, CVE-2016-2396 is exploitable remotely by authenticated users, making it particularly concerning for system security.