CVE-2024-45315

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Nov 1, 2024
CWE ID 59

Summary

CVE-2024-45315 is a vulnerability affecting SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client). This issue involves improper link resolution before file access, also known as 'Link Following.' Users with standard privileges can exploit this vulnerability to create arbitrary folders and files, potentially causing local Denial of Service (DoS) attacks. This weakness could allow attackers to disrupt the normal functioning of the SonicWall Connect Tunnel software. Users are urged to update their software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share