RULE(RULE ID:314986)

Rule General Information
Release Date: 2013-12-23
Rule Name: WEB-ACTIVEX SonicWALL SSL VPN End Point Interrogator Installer ActiveX Control code execution
Severity:
CVE ID:
Rule Protection Details
Description: There exists a code execution vulnerability in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX controls. Specifically, the vulnerability is due to a format string error in the "epi.dll" library when creating a log message. This can be exploited by assigning a specially crafted string value to affected properties of the ActiveX control.
Impact: Remote code execution
Affected OS: Network Device, Solaris, FreeBSD, Windows, Other Unix, Linux
Reference: SecurityAdvisory:SA41026
KBID:8272
NSOADV-2010-005
Solutions
Update vendor's patch.