Impact
The SonicWall NetExtender Linux client’s auto‑upgrade process does not securely handle temporary files, permitting an attacker to manipulate file paths during upgrade. This flaw falls under CWE‑59, a path traversal weakness that can enable unauthorized overwrite or creation of files on the system. While the description does not explicitly state the resulting impact, the ability to modify file paths could allow an attacker to replace legitimate binaries or configuration files, potentially leading to privilege escalation or denial of service if critical components are corrupted.
Affected Systems
SonicWall NetExtender on Linux platforms. No specific version ranges are disclosed; the vulnerability applies to all instances of the NetExtender client that utilize the NEService auto‑upgrade functionality.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits to date. The CVSS score is 7, which places the vulnerability in the medium‑severity range. The path traversal weakness in the auto‑upgrade component suggests that, if exploitable, an attacker could write arbitrary files to the system, potentially compromising integrity and enabling privilege escalation or denial of service. The likely attack vector requires access to the auto‑upgrade process, such as a compromised local user or a trigger over a network connection, but the precise prerequisites are not detailed in the available information.
OpenCVE Enrichment