CVE-2024-29014

Published Jul 18, 2024

Last updated 5 months ago

Overview

Description
Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.
Source
PSIRT@sonicwall.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

PSIRT@sonicwall.com
CWE-94

Social media

Hype score
Not currently trending
  1. #ITSecurity Researchers reveal exploitable flaws in corporate VPN clients Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute…

    @seaarepea

    1 Dec 2024

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Threat Alert: New NachoVPN attack uses rogue VPN servers to install malicious updates CVE-2024-29014 CVE-2024-5921 Severity: ⚠️ Critical Maturity: 💥 Mainstream Learn more: https://t.co/9cTrCvs1qO #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    27 Nov 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. パロアルトネットワークス社とSonicWallのVPNにおける悪用可能な脆弱性が開示された。CVE-2024-5921はパロアルト社GlobalProtectの各クライアントを任意のサーバに接続させることができ、悪意あるroot証明書の導入につながる可能性。 https://t.co/eKoOCRikrx CVE-2024-29014はSoniWallのNetExtender… https://t.co/44w8DfJOoL

    @__kokumoto

    26 Nov 2024

    3556 Impressions

    16 Retweets

    53 Likes

    9 Bookmarks

    1 Reply

    0 Quotes

  4. Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵

    @AmberWolfSec

    26 Nov 2024

    6980 Impressions

    24 Retweets

    47 Likes

    13 Bookmarks

    1 Reply

    2 Quotes

Configurations