CVE-2018-9866
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 4.5%
from disclosure to weapon
Published on NVDAug 3
VulnCheck+85d
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SonicWall · Global Management System (GMS)