Format string error in SonicOS - CVE-2024-12805
Published: January 8, 2025
SonicOS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to a format string error within management interface. A remote privileged user can send a specially crafted HTTP request that contains format string specifiers and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.