QID 375947

Date Published: 2021-10-13

QID 375947: SonicWall Global Virtual Private Network (VPN) Client Privilege Escalation Vulnerability

SonicWall VPN Clients offer a flexible easy-to-use, easy-to-manage Virtual Private Network (VPN) solution that provides distributed and mobile users with secure, reliable remote access to corporate assets via broadband, wireless and dial-up connections.

Affected version:
SonicWall Global VPN Client 4.10.5 and earlier

QID Detection Logic:
This QID detects the vulnerable version from the SonicWall Global VPN Client Executable.

Successful exploitation of the vulnerability may lead to privilege escalation which potentially allows command execution in the host operating system

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Vendor has released patch. For more details, please refer to SNWLID-2021-0024
    Vendor References

    CVEs related to QID 375947

    Software Advisories
    Advisory ID Software Component Link
    SNWLID-2021-0024 URL Logo psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0024