- Description
- Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.
- Source
- PSIRT@sonicwall.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- PSIRT@sonicwall.com
- CWE-94
- Hype score
- Not currently trending
#ITSecurity Researchers reveal exploitable flaws in corporate VPN clients Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute…
@seaarepea
1 Dec 2024
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Threat Alert: New NachoVPN attack uses rogue VPN servers to install malicious updates CVE-2024-29014 CVE-2024-5921 Severity: ⚠️ Critical Maturity: 💥 Mainstream Learn more: https://t.co/9cTrCvs1qO #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
27 Nov 2024
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
パロアルトネットワークス社とSonicWallのVPNにおける悪用可能な脆弱性が開示された。CVE-2024-5921はパロアルト社GlobalProtectの各クライアントを任意のサーバに接続させることができ、悪意あるroot証明書の導入につながる可能性。 https://t.co/eKoOCRikrx CVE-2024-29014はSoniWallのNetExtender… https://t.co/44w8DfJOoL
@__kokumoto
26 Nov 2024
3556 Impressions
16 Retweets
53 Likes
9 Bookmarks
1 Reply
0 Quotes
Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵
@AmberWolfSec
26 Nov 2024
6980 Impressions
24 Retweets
47 Likes
13 Bookmarks
1 Reply
2 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "E46B90F9-C6DD-44B8-AE8A-ABE37FF22D3E",
"versionEndExcluding": "10.2.341"
}
],
"operator": "OR"
}
]
}
]