Vulnerability record · CVE-2013-1359 · published 11 February 2020
CVE-2013-1359: SonicWALL UMA authentication bypass via skipSessionCheck grants root
Sonicwall · Analyzer
An improper authentication flaw (CWE-287) in multiple Dell SonicWALL management products allows bypassing session checks through the skipSessionCheck parameter on the UMA interface (/appliance/). Because the bypass yields access to the root account, it is a full compromise of the affected management appliance.
Description
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable bypass leading to root access, with public exploit code and a very high EPSS score, makes this an urgent exposure for any internet-facing or unpatched appliance.
What it is
An improper authentication flaw (CWE-287) in multiple Dell SonicWALL management products allows bypassing session checks through the skipSessionCheck parameter on the UMA interface (/appliance/). Because the bypass yields access to the root account, it is a full compromise of the affected management appliance.
Impact
An unauthenticated remote attacker gains root-level access to the management appliance, allowing full control of the device and any managed security infrastructure it administers.
Attack surface
Reachable over the network via the UMA web interface at /appliance/ by supplying the skipSessionCheck parameter; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists (Exploit-DB, Packet Storm, Full Disclosure references), but the CVE is not in CISA KEV and no ransomware use is documented; EPSS is very high at 0.894 (99.8th percentile), indicating strong predicted exploitation activity.
What to do
- Apply the vendor patch or fixed firmware for the affected SonicWALL Analyzer, GMS, UMA and ViewPoint versions; if no fix is available, retire or isolate the product.
- Remove direct internet exposure of the UMA interface (/appliance/) and restrict management access to a dedicated, tightly controlled network.
- Enforce firewall rules and reverse-proxy filtering that block requests carrying the skipSessionCheck parameter.
- Rotate root and administrative credentials on any appliance that may have been exposed, and review for unauthorized configuration changes.
- Monitor vendor advisories for updated guidance since the record does not list fixed versions.
Detection
- Search web and proxy logs for requests to /appliance/ containing the skipSessionCheck parameter.
- Alert on successful authentication or root-level sessions originating from unexpected source IPs on management appliances.
- Audit appliance logs for configuration changes, new admin accounts, or session activity that does not follow a normal login sequence.
- Use the FortiGuard IPS signature for multiple SonicWALL products authentication bypass to detect exploitation attempts at the network edge.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1359 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1359), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.