SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.
References
| Link | Resource |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0019 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Jan 2024, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-787 | |
| First Time |
Sonicwall
Sonicwall netextender Sonicwall capture Client |
|
| CPE | cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:* cpe:2.3:a:sonicwall:capture_client:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0019 - Vendor Advisory |
18 Jan 2024, 13:42
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-01-18 00:15
Updated : 2024-01-29 17:17
NVD link : CVE-2023-6340
Mitre link : CVE-2023-6340
CVE.ORG link : CVE-2023-6340
JSON object : View
Products Affected
sonicwall
- netextender
- capture_client
