CVE-2020-5145 Vulnerability Details

  /     /     /  

CVE-2020-5145 Metadata Quick Info

CVE Published: 28/10/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: sonicwall | Vendor: SonicWall | Product: SonicWall Global VPN Client
Status : PUBLISHED

CVE-2020-5145 Description

SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-427
CWE Name: CWE-427: Uncontrolled Search Path Element
Source: SonicWall

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).