{"cve":"CVE-2018-9866","epss":{"score":0.04504},"mitre":{"cpes":[],"created":"2018-08-03T20:00:00+00:00","description":"A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2018/9xxx/CVE-2018-9866.json","references":["https://github.com/rapid7/metasploit-framework/pull/10305","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007","https://twitter.com/ddouhine/status/1019251292202586112"],"title":null,"updated":"2025-05-05T19:08:14.640000+00:00","vendors":[],"weaknesses":["CWE-77"]},"nvd":{"cpes":["cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*"],"created":"2018-08-03T20:29:00.343000+00:00","description":"A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2018/CVE-2018-9866.json","references":["https://github.com/rapid7/metasploit-framework/pull/10305","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007","https://twitter.com/ddouhine/status/1019251292202586112"],"title":null,"updated":"2026-06-17T02:07:18.890000+00:00","vendors":["sonicwall","sonicwall$PRODUCT$global_management_system"],"weaknesses":["CWE-20","CWE-77"]},"opencve":{"changes":[{"created":"2025-05-05T19:15:00+00:00","data":[{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"4c820efd-0f79-4dff-91bc-4dee94b49f68"}],"cpes":{"data":["cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2018-08-03T20:00:00+00:00","provider":"mitre"},"description":{"data":"A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.04504},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/rapid7/metasploit-framework/pull/10305","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007","https://twitter.com/ddouhine/status/1019251292202586112"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-05-05T19:15:52.430000+00:00","provider":"nvd"},"vendors":{"data":["sonicwall","sonicwall$PRODUCT$global_management_system"],"providers":["nvd"]},"weaknesses":{"data":["CWE-20","CWE-77"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2018-08-03T20:00:00+00:00","description":"A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2025-05-05T13:21:16.613000+00:00","vendors":[],"vulnrichment_repo_path":"2018/9xxx/CVE-2018-9866.json","weaknesses":[]}}