ID

VAR-201511-0256


CVE

CVE-2015-7770


TITLE

SonicWall TotalSecure TZ 100 Series vulnerable to denial-of-service (DoS)

Trust: 0.8

sources: JVNDB: JVNDB-2015-000176

DESCRIPTION

Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet. SonicWall TotalSecure TZ 100 Series is a firewall product provided by Dell Inc. SonicWall TotalSecure TZ 100 Series contains a denial-of-service (DoS) vulnerability. FFRI,Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.Processing a specially crafted packet may lead to a denial-of-service (DoS). An attacker can exploit this issue to cause a denial-of-service condition. Dell SonicWall TotalSecure TZ 100 is a Unified Threat Management (UTM) firewall from Dell, USA, that provides functions such as intrusion prevention, anti-malware, content/URL filtering, and application control

Trust: 1.98

sources: NVD: CVE-2015-7770 // JVNDB: JVNDB-2015-000176 // BID: 77499 // VULHUB: VHN-85731

AFFECTED PRODUCTS

vendor:dellmodel:sonicwall totalsecure tz 100scope:lteversion:5.9.1.0

Trust: 1.0

vendor:dellmodel:sonicwall totalsecure tz 100 seriesscope:eqversion:prior to 5.9.1.0-22o

Trust: 0.8

vendor:dellmodel:sonicwall totalsecure tz 100scope:eqversion:5.9.1.0

Trust: 0.6

vendor:dellmodel:sonicwall totalsecure tz seriesscope:eqversion:1000

Trust: 0.3

vendor:dellmodel:sonicwall totalsecure tz series 5.9.1.0-22oscope:neversion:100

Trust: 0.3

sources: BID: 77499 // JVNDB: JVNDB-2015-000176 // CNNVD: CNNVD-201511-108 // NVD: CVE-2015-7770

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-7770
value: MEDIUM

Trust: 1.0

IPA: JVNDB-2015-000176
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201511-108
value: MEDIUM

Trust: 0.6

VULHUB: VHN-85731
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-7770
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

IPA: JVNDB-2015-000176
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-85731
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-85731 // JVNDB: JVNDB-2015-000176 // CNNVD: CNNVD-201511-108 // NVD: CVE-2015-7770

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-85731 // JVNDB: JVNDB-2015-000176 // NVD: CVE-2015-7770

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201511-108

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201511-108

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-000176

PATCH

title:SonicWALL TZ Seriesurl:https://support.software.dell.com/sonicwall-tz-series/100

Trust: 0.8

title:Dell SonicWall TotalSecure TZ 100 Enter the fix for the verification vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=58603

Trust: 0.6

sources: JVNDB: JVNDB-2015-000176 // CNNVD: CNNVD-201511-108

EXTERNAL IDS

db:JVNid:JVN90135579

Trust: 2.8

db:NVDid:CVE-2015-7770

Trust: 2.8

db:JVNDBid:JVNDB-2015-000176

Trust: 2.5

db:SECTRACKid:1034092

Trust: 1.1

db:CNNVDid:CNNVD-201511-108

Trust: 0.7

db:BIDid:77499

Trust: 0.4

db:SEEBUGid:SSVID-89771

Trust: 0.1

db:VULHUBid:VHN-85731

Trust: 0.1

sources: VULHUB: VHN-85731 // BID: 77499 // JVNDB: JVNDB-2015-000176 // CNNVD: CNNVD-201511-108 // NVD: CVE-2015-7770

REFERENCES

url:http://jvn.jp/en/jp/jvn90135579/index.html

Trust: 2.8

url:http://jvndb.jvn.jp/jvndb/jvndb-2015-000176

Trust: 1.7

url:http://www.securitytracker.com/id/1034092

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-7770

Trust: 0.8

url:https://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-7770

Trust: 0.8

url:https://support.software.dell.com/sonicwall-tz-series/100

Trust: 0.3

sources: VULHUB: VHN-85731 // BID: 77499 // JVNDB: JVNDB-2015-000176 // CNNVD: CNNVD-201511-108 // NVD: CVE-2015-7770

CREDITS

FFRI,Inc

Trust: 0.3

sources: BID: 77499

SOURCES

db:VULHUBid:VHN-85731
db:BIDid:77499
db:JVNDBid:JVNDB-2015-000176
db:CNNVDid:CNNVD-201511-108
db:NVDid:CVE-2015-7770

LAST UPDATE DATE

2025-04-13T23:09:43.956000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-85731date:2016-12-07T00:00:00
db:BIDid:77499date:2015-11-06T00:00:00
db:JVNDBid:JVNDB-2015-000176date:2015-11-09T00:00:00
db:CNNVDid:CNNVD-201511-108date:2015-11-09T00:00:00
db:NVDid:CVE-2015-7770date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-85731date:2015-11-06T00:00:00
db:BIDid:77499date:2015-11-06T00:00:00
db:JVNDBid:JVNDB-2015-000176date:2015-11-06T00:00:00
db:CNNVDid:CNNVD-201511-108date:2015-11-09T00:00:00
db:NVDid:CVE-2015-7770date:2015-11-06T11:59:05.807