MEDIUM · 5.4

CVE-2018-5281

SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

Vulnerability Description

SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
SonicwallSonicosAll versions
SonicwallNsa 250M-
SonicwallNsa 2600-
SonicwallNsa 2650-
SonicwallNsa 3600-
SonicwallNsa 4600-
SonicwallNsa 5600-
SonicwallNsa 6600-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-5281?

CVE-2018-5281 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

How severe is CVE-2018-5281?

CVE-2018-5281 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-5281?

Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Sonicos, Sonicwall Nsa 250M, Sonicwall Nsa 2600, Sonicwall Nsa 2650, Sonicwall Nsa 3600.