« Volver al listado

CVE-2023-44220

Estado: ModificadaAlta (7.3)—

SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-44220",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-44220",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-09T15:16:01.758354Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@sonicwall.com",
      "affectedData": [
        {
          "vendor": "SonicWall",
          "product": "NetExtender",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.336 and earlier versions"
            }
          ],
          "platforms": [
            "Windows",
            "32 bit",
            "64 bit"
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:sonicwall:netextender:10.2.336:*:*:*:*:windows:*:*"
          ],
          "vendor": "sonicwall",
          "product": "netextender",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "10.2.336",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-10-27T08:15:31.207",
  "references": [
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0017",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@sonicwall.com"
    },
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0017",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@sonicwall.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system."
    },
    {
      "lang": "es",
      "value": "El cliente SonicWall NetExtender Windows (32 bits y 64 bits) 10.2.336 y versiones anteriores tienen una vulnerabilidad de Secuestro de Orden de Búsqueda de DLL en el componente DLL de inicio. La explotación exitosa a través de un atacante local podría resultar en la ejecución de comandos en el sistema de destino."
    }
  ],
  "lastModified": "2026-06-17T06:27:09.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sonicwall:netextender:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F79C094F-9986-4B09-800D-2F1DBE23B8FD",
              "versionEndIncluding": "10.2.336"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT@sonicwall.com"
}