SonicWall Releases NSM Security Update
Out-of-band updates for SonicWall Network Security Manager products
Summary
Out-of-band updates for SonicWall Network Security Manager products
Affected platforms
The following platforms are known to be affected:
SonicWall Network Security Manager (NSM) Versions: all prior to and including 2.2.0-R10-H1
Threat details
Introduction
SonicWall has validated and patched a post-authentication vulnerability (SNWLID-2021-0014) within the on-premises version of Network Security Manager (NSM). This critical vulnerability potentially allows a user to execute commands on a device’s operating system with the highest system privileges (root).
Remediation advice
Organisations are encouraged to review the Network Security Manager (NSM) Command Injection Vulnerability page and apply the necessary update.
CVE Vulnerabilities
Last edited: 1 June 2021 2:18 pm