Skip to main content
  1. Home
  2. Computing
  3. Business
  4. Mobile
  5. Web
  6. News

Dell just patched a nasty bug that might have left your work PC exposed

Add as a preferred source on Google

Dell recently distributed a hotfix that addresses vulnerabilities found in the Dell SonicWALL Global Management System (GMS) and SonicWALL Analyzer, versions 8.0 and 8.1. Both solutions are typically installed on PCs distributed in corporations and businesses, the former of which is used to manage, report, and monitor SonicWALL appliances like SSL VPNs and firewalls. Analyzer provides web-based network traffic analysis and reporting tools.

“Vulnerabilities were found pertaining to command injection, unauthorized XXE, default account, and unauthorized modification of virtual appliance networking information,” the company states. “To fix these vulnerabilities, Dell highly recommends that existing users of Dell SonicWALL GMS and Analyzer Hotfix 174525.”

Recommended Videos

The vulnerabilities in Dell’s two SonicWALL solutions were uncovered by Digital Defense Incorporated. This company was founded in 1999, and provides managed security assessment solutions for small businesses and Fortune companies alike in over 65 countries. The firm actually discovered up to six vulnerabilities just in Dell’s SonicWALL GMS service alone.

According to the security firm, the vulnerabilities include unauthenticated remote command execution with root privileges, a hidden default account with an easily guessable password, an unauthenticated XML External Entity (XXE) injection in the GMC service, an unauthenticated XML External Entity (XXE) injection via a crafted AMF message, and unauthenticated network configuration changes via the GMC service.

For instance, if the attacker uses the command injection vulnerability, the crafty individual can gain a reverse root shell on the virtual appliance. This enables the attacker to grab database credentials and change the password, preventing the administrator of the GMS to access the interface and giving the attacker full control over the virtual appliance.

As for the hidden account, this can be used to add non-administrative users through the CLI Client made available to download through the GMS web application. These users can then log onto the web interfaces and change the administrator’s password. Their privileges can thus be elevated by logging out and logging back in as administrator with a new password. That means full control of the GMS interface and all connected SonicWALL appliances.

As for some of the other vulnerabilities, hackers could use XXE injection to retrieve encrypted database credentials and IP addresses, and use a static key to decrypt and change the administrator’s password. XXE injection could also be used to retrieve the current MD5 password hash for the administrator of the virtual appliance. The last several hashed passwords for the administrator can be obtained too.

“Users who are unable to apply patches to the affected systems can attempt to mitigate some of the risk posed by these exploit vectors by limiting access to the network services of their SonicWALL GMS appliances to restricted-access internal network segments or dedicated VLANs,” the firm reports.

Top get the hotfix from Dell, customers can simply download it from here. Just log onto MySonicWALL, click on “Downloads” and then “Download Center” in the navigation panel on the left. After that, choose “GMS / Analyzer – Virtual Appliance” or “GMS / Analyzer – Windows” in the drop down menu labeled “Software Type.” After that, follow the release notes for detailed instructions on how to install the hotfix.

For a detailed accounting of each vulnerability that’s now patched by Dell, check out Digital Defense’s blog right here.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
If you miss the feel of paper in the digital age, this app gives your Mac’s screen a textured look
A paper-like screen overlay could make long work sessions feel less harsh.
Advertisement, Poster, Electronics

Most screen-comfort tools work by changing color temperature. Apple’s Night Shift makes the screen warmer, often giving everything an orange tint. Paperman is an interesting alternative because it adds a subtle paper-like texture over the display instead.

The app is available for Mac and Windows, and it is designed to make a screen look closer to paper, matte glass, or an e-ink display. It softens the harsh contrast and reduces the glossy look of modern screens during long reading or writing sessions.

Read more
I dug these last-hour Prime Day smart home, laptop, and accessory deals that are irresistible
Deals up to 60% off, a few hours left, and no reason to wait any longer.
Electronics, Phone, Speaker

Amazon's Prime Day 2026 sale is in its final hours, giving you your last chance to get your hands on the best smart home, security, tablet, laptop, and accessory deals. I've pulled together the picks that are still live, still deeply discounted, and still worth buying before the sale ends tonight or until the stock lasts.

Best Amazon Prime Day deals on smart home devices

Read more
Apple’s biggest MacBook Pro redesign in years may skip the chip everyone expected
The next MacBook Pro may bring OLED and touch support without M6 Pro silicon
MacBook Pro on Table

Apple is expected to launch a refreshed MacBook Pro later this year, but according to Bloomberg, it won't come equipped with a next-gen processor. Instead, Apple is going to equip the highly anticipated device with Pro and Max variants of the current-gen M5 silicon.

It was widely speculated that when the redesigned MacBook with an OLED display and touch-screen capability debuts, it will also mark the arrival of the M6 series processors. Well, it appears that Apple has changed its silicon strategy pretty significantly.

Read more