MEDIUM · 5.4

CVE-2018-5280

SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

Vulnerability Description

SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
SonicwallSonicos6.2.7.0
SonicwallNsa 250M-
SonicwallNsa 2600-
SonicwallNsa 2650-
SonicwallNsa 3600-
SonicwallNsa 4600-
SonicwallNsa 5600-
SonicwallNsa 6600-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-5280?

CVE-2018-5280 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

How severe is CVE-2018-5280?

CVE-2018-5280 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-5280?

Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Sonicos, Sonicwall Nsa 250M, Sonicwall Nsa 2600, Sonicwall Nsa 2650, Sonicwall Nsa 3600.