轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202608-00000011
[內容說明]
SonicWall 針對旗下產品 GMS 發布重大資安漏洞公告 (CVE-2026-66145,CVSS:9.1與CVE-2026-66147,CVSS:9.4)。CVE-2026-66145為未經身分驗證的遠端程式碼執行漏洞,允許遠端攻擊者透過zipslip 讀取敏感資料並執行任意檔案寫入;CVE-2026-66147為未經身分驗證的命令注入漏洞,允許遠端攻擊者可透過精心設計的請求執行遠端程式碼。
[影響平台]
SonicWall GMS 9.5.1(含)之前版本
[建議措施]
請將SonicWall GMS更新至 9.5.2(含)之後版本
[參考資料]
1. https://www.twcert.org.tw/tw/cp-169-11103-13b85-1.html
Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202608-00000011
[Content Description]
SonicWall has released a critical cybersecurity vulnerability bulletin for its product GMS (CVE-2026-66145, CVSS: 9.1 and CVE-2026-66147, CVSS: 9.4). CVE-2026-66145 is an unauthenticated remote code execution vulnerability, allowing a remote attacker to read sensitive data and perform arbitrary file writes via zipslip; CVE-2026-66147 is an unauthenticated command injection vulnerability, allowing a remote attacker to execute remote code through a carefully crafted request.
[Affected Platforms]
SonicWall GMS versions 9.5.1 and earlier
[Recommended Action]
Please update SonicWall GMS to version 9.5.2 or later.
[References]
1. https://www.twcert.org.tw/tw/cp-169-11103-13b85-1.html