First published: Mon Jan 08 2018(Updated: )
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | =6.2.7.0 | |
SonicWall SonicOS | =6.2.9.0 | |
SonicWall SonicOS | =6.5.0.0 | |
SonicWall SonicOS | =6.5.1.0 | |
SonicWall SonicOS | =6.5.2.0 | |
Sonicwall Nsa 250m | ||
Sonicwall Nsa 2600 | ||
Sonicwall Nsa 2650 | ||
Sonicwall Nsa 3600 | ||
Sonicwall Nsa 4600 | ||
Sonicwall Nsa 5600 | ||
Sonicwall Nsa 6600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5280 is a vulnerability found in SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices that allows for cross-site scripting (XSS) attacks via the Configure SSO screens.
CVE-2018-5280 has a severity score of 5.4, which is considered medium.
SonicWall SonicOS versions 6.2.7.0, 6.2.9.0, 6.5.0.0, and 6.5.1.0 are affected by CVE-2018-5280.
To fix CVE-2018-5280, update to the latest version of SonicWall SonicOS.
You can find more information about CVE-2018-5280 at the following references: [securityfocus.com](http://www.securityfocus.com/bid/102438), [psirt.global.sonicwall.com](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0001), [vulnerability-lab.com](https://www.vulnerability-lab.com/get_content.php?id=1725).