tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ssl_vpn | Nortel | * | 4.2.1.6 (including) |
Ssl_vpn | Nortel | 4.1.2.11 (including) | 4.1.2.11 (including) |
Ssl_vpn | Nortel | 4.1.2.12 (including) | 4.1.2.12 (including) |