← Vulnerability feed

Vulnerability record · CVE-2013-1359 · published 11 February 2020

CVE-2013-1359: SonicWALL UMA authentication bypass via skipSessionCheck grants root

Sonicwall · Analyzer

An improper authentication flaw (CWE-287) in multiple Dell SonicWALL management products allows bypassing session checks through the skipSessionCheck parameter on the UMA interface (/appliance/). Because the bypass yields access to the root account, it is a full compromise of the affected management appliance.

9.8 CVSS 3.1 Critical EPSS 89% · top 0.2% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
16References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable bypass leading to root access, with public exploit code and a very high EPSS score, makes this an urgent exposure for any internet-facing or unpatched appliance.

What it is

An improper authentication flaw (CWE-287) in multiple Dell SonicWALL management products allows bypassing session checks through the skipSessionCheck parameter on the UMA interface (/appliance/). Because the bypass yields access to the root account, it is a full compromise of the affected management appliance.

Impact

An unauthenticated remote attacker gains root-level access to the management appliance, allowing full control of the device and any managed security infrastructure it administers.

Attack surface

Reachable over the network via the UMA web interface at /appliance/ by supplying the skipSessionCheck parameter; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Public exploit code exists (Exploit-DB, Packet Storm, Full Disclosure references), but the CVE is not in CISA KEV and no ransomware use is documented; EPSS is very high at 0.894 (99.8th percentile), indicating strong predicted exploitation activity.

What to do

  • Apply the vendor patch or fixed firmware for the affected SonicWALL Analyzer, GMS, UMA and ViewPoint versions; if no fix is available, retire or isolate the product.
  • Remove direct internet exposure of the UMA interface (/appliance/) and restrict management access to a dedicated, tightly controlled network.
  • Enforce firewall rules and reverse-proxy filtering that block requests carrying the skipSessionCheck parameter.
  • Rotate root and administrative credentials on any appliance that may have been exposed, and review for unauthorized configuration changes.
  • Monitor vendor advisories for updated guidance since the record does not list fixed versions.

Detection

  • Search web and proxy logs for requests to /appliance/ containing the skipSessionCheck parameter.
  • Alert on successful authentication or root-level sessions originating from unexpected source IPs on management appliances.
  • Audit appliance logs for configuration changes, new admin accounts, or session activity that does not follow a normal login sequence.
  • Use the FortiGuard IPS signature for multiple SonicWALL products authentication bypass to detect exploitation attempts at the network edge.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1359 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-2396Sonicwall analyzer command injection vulnerabilityThe GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…EPSS 4.7%9.8CVE-2023-34132Sonicwall analytics vulnerabilityUse of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff…EPSS 7.7%9.8CVE-2023-34136Sonicwall analytics unrestricted file upload vulnerabilityVulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…EPSS 0.80%9.8CVE-2023-34137Sonicwall analytics improper authentication vulnerabilitySonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …EPSS 1.0%9.8CVE-2023-34130Sonicwall analytics broken cryptographic algorithm vulnerabilitySonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.…EPSS 0.31%9.8CVE-2023-34124SonicWall GMS and Analytics Web Services authentication bypassThe authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass…EPSS 50%analysed9.8CVE-2023-34128Sonicwall analytics insufficiently protected credentials vulnerabilityTomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…EPSS 0.71%9.8CVE-2022-22280Sonicwall analytics sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…EPSS 9.5%

Source: NIST National Vulnerability Database (record CVE-2013-1359), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.