CVE-2018-5281: XSS
Published Jan 8, 2018
·Updated
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
Affected Software
8 affected components
SonicWall SonicOS
SonicWall Nsa 250m
SonicWall Nsa 2600
SonicWall Nsa 2650
SonicWall Nsa 3600
SonicWall Nsa 4600
SonicWall Nsa 5600
SonicWall Nsa 6600
Event History
Jan 8, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-5281?
CVE-2018-5281 is a vulnerability in SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices that allows for cross-site scripting (XSS) attacks.
2
What is the severity of CVE-2018-5281?
CVE-2018-5281 has a severity rating of medium with a CVSS score of 5.4.
3
How does CVE-2018-5281 affect SonicWall SonicOS?
CVE-2018-5281 affects SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices.
4
What is the impact of CVE-2018-5281?
CVE-2018-5281 allows attackers to perform cross-site scripting (XSS) attacks.
5
How can I fix CVE-2018-5281?
To fix CVE-2018-5281, it is recommended to apply the latest patches and updates from SonicWall.