2023-10-03 10:00:28 +00:00
{
"id" : "CVE-2023-44218" ,
"sourceIdentifier" : "PSIRT@sonicwall.com" ,
"published" : "2023-10-03T08:15:36.067" ,
2023-10-04 18:00:29 +00:00
"lastModified" : "2023-10-04T17:49:26.270" ,
"vulnStatus" : "Analyzed" ,
2023-10-03 10:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "\nA flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.\n\n"
2023-10-03 14:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una falla dentro de la funci\u00f3n SonicWall NetExtender Pre-Logon permite que un usuario no autorizado obtenga acceso al sistema operativo Windows host con privilegios de nivel 'SYSTEM', lo que genera una vulnerabilidad de escalada de privilegios local (LPE)."
2023-10-03 10:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-10-04 18:00:29 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
} ,
2023-10-03 10:00:28 +00:00
{
"source" : "PSIRT@sonicwall.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
2023-10-04 18:00:29 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2023-10-03 10:00:28 +00:00
{
"source" : "PSIRT@sonicwall.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-267"
}
]
}
] ,
2023-10-04 18:00:29 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*" ,
"versionEndIncluding" : "10.2.336" ,
"matchCriteriaId" : "F79C094F-9986-4B09-800D-2F1DBE23B8FD"
}
]
}
]
}
] ,
2023-10-03 10:00:28 +00:00
"references" : [
{
"url" : "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0014" ,
2023-10-04 18:00:29 +00:00
"source" : "PSIRT@sonicwall.com" ,
"tags" : [
"Vendor Advisory"
]
2023-10-03 10:00:28 +00:00
}
]
}