CVE-2019-7474: Medium severity sonicwall sonicos vulnerability
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading certificate with specific extension. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8vRC363 (VMWARE), 6.5.0.2.8vRC367 (AZURE), SonicOSv 6.5.0.2.8vRC368 (AWS), SonicOSv 6.5.0.2.8vRC366 (HYPERV).
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2019-7474?
Vulnerability CVE-2019-7474 is a vulnerability in SonicWall SonicOS and SonicOSv that allows an authenticated read-only admin to leave the firewall in an unstable state by downloading a certificate with a specific extension.
Which versions of SonicOS are affected by CVE-2019-7474?
SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3, and SonicOSv version 6.5.0.2-8v_rc363, 6.5.0.2.8v_rc366, 6.5.0.2.8v_rc367, and 6.5.0.2.8v_rc368 are affected by CVE-2019-7474.
What is the severity of vulnerability CVE-2019-7474?
The severity of vulnerability CVE-2019-7474 is medium with a severity value of 6.5.
How can I fix vulnerability CVE-2019-7474?
Apply the necessary patches and updates provided by SonicWall to fix vulnerability CVE-2019-7474.
Where can I find more information about vulnerability CVE-2019-7474?
You can find more information about vulnerability CVE-2019-7474 on the SonicWall PSIRT website: [https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0001](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0001)