CVE-2018-9866: Input Validation
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9866?
The severity of CVE-2018-9866 is critical with a score of 9.8 out of 10.
Which software is affected by CVE-2018-9866?
SonicWALL Global Management System (GMS) version 8.1 and earlier is affected by CVE-2018-9866.
How does CVE-2018-9866 impact the affected software?
CVE-2018-9866 allows a remote user to execute arbitrary code on the affected SonicWALL Global Management System (GMS) virtual appliance.
Is there a fix available for CVE-2018-9866?
Yes, updating to a version later than 8.1 of SonicWALL Global Management System (GMS) resolves the vulnerability.
Where can I find more information about CVE-2018-9866?
You can find more information about CVE-2018-9866 on the following references: [Github](https://github.com/rapid7/metasploit-framework/pull/10305), [SonicWall](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007), [Twitter](https://twitter.com/ddouhine/status/1019251292202586112).