Impact
The updated CVE description reveals a path traversal flaw in the file extractor of the SonicWall NetExtender Linux client that allows an attacker to write an arbitrary file as root. This capability effectively grants full control over the affected host, leading to potential remote code execution or persistent compromise.
Affected Systems
SonicWall NetExtender for Linux. Exact versions are not disclosed, so all current releases of the NetExtender client are potentially affected.
Risk and Exploitability
The vulnerability confers the ability to overwrite critical system files as root. The CVSS score is 8.8 and the EPSS score is less than 1%. It is not listed in the CISA KEV catalog, but the impact is severe. Exploitation requires the attacker to supply a crafted tarball or otherwise trigger the vulnerable extraction routine. The attack vector is not explicitly specified in the description; based on the nature of the flaw it is inferred that this could involve local privilege escalation or tricking a user to run the extractor. Because it elevates privileges and allows arbitrary file writes, it can lead to remote code execution or persistent backdoor installation.
OpenCVE Enrichment