6.8
CVSSv2

CVE-2015-2248

Published: 01/05/2015 Updated: 12/03/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware prior to 7.5.1.0-38sv and 8.x prior to 8.0.0.1-16sv allows remote malicious users to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.

Vulnerable Product Search on Vulmon Subscribe to Product

sonicwall remote access firmware

Exploits

# Exploit Title: Dell SonicWALL Secure Remote Access (SRA) Appliance Cross-Site Request Forgery # Date: 04/28/2015 # Exploit Author: Veit Hailperin # Vendor Homepage: wwwdellcom # Version: Dell SonicWALL SRA 75 prior to 7510-38sv and 80 prior to 8001-16sv # CVE : 2015-2248 Exploitation Procedure (Outline): 1 Use CSRF to force currentl ...