CVE-2016-2397

CRITICAL

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafte...

Affects 4 products across 1 vendor.

BCS7.68
CVSS 3.09.8
EPSS6.4%
Percentile93th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-77: Command Injection

Attacker injects operating system commands through application inputs passed to a shell or system call.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-77
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-77
CAPEC-15 Command Delimiters
via CWE-77
CAPEC-40 Manipulating Writeable Terminal Devices
via CWE-77
CAPEC-75 Manipulating Writeable Configuration Files
via CWE-77
Show all 8
via CWE-77
via CWE-77
via CWE-77

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2016. A critical vulnerability affects Sonicwall systems (CVE-2016-2397). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2016-GLOBAL-258794-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2016-2397?
This vulnerability was disclosed in 2016. A critical vulnerability affects Sonicwall systems (CVE-2016-2397). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2016-2397?
CVE-2016-2397 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 6.4%.
Is CVE-2016-2397 actively exploited?
No confirmed active exploitation of CVE-2016-2397 as of 2026-09-25.
How do I remediate CVE-2016-2397?
Priority: MEDIUM. Advisory: https://support.software.dell.com/product-notification/185943 PSIRT: [email protected]
What systems are affected by CVE-2016-2397?
CVE-2016-2397 affects: Sonicwall, Sonicwall, Sonicwall, Sonicwall.
Vulnerability Details
CVE IDCVE-2016-2397
BSIDBS-2016-GLOBAL-258794-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2016-02-17
Last Modified2026-06-17
ICS Relevance100%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Sonicwall Analyzer —
Sonicwall Global Management System —
Sonicwall Uma Em5000 —
Sonicwall Uma Em5000 Firmware —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 3876 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash3c8052b63fb5c12c0b07396042ebf4417f64bb794ea8989404d097c73e49fc6e38b946f3a58328597f534ec031d9cf282810e680757eef4aa893d82c9f0ea477
Related CVEs affecting Sonicwall
CVE-2026-83548 10.0 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work ... CVE-2007-5815 10.0 Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control ... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2026-15409 10.0 A Server-side request forgery (SSRF) vulnerability has been identified in the... CVE-2016-2396 9.9 The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, an...
View all Sonicwall CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →