CVE-2019-7484: SQL Injection
Published Dec 19, 2019
·Updated
Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
Affected Software
2 affected components
SonicWall Sma 100 Firmware<=9.0.0.3
SonicWall SMA 100
Event History
Dec 19, 2019
CVE Published
via MITRE·12:35 AM
Data Sourced
via MITRE·12:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-7484?
CVE-2019-7484 is a vulnerability in SonicWall SMA100 that allows an authenticated user to gain read-only access to unauthorized resources using the viewcacert CGI script.
2
Which version of SMA100 is affected by CVE-2019-7484?
SMA100 version 9.0.0.3 and earlier are affected by CVE-2019-7484.
3
What is the severity of CVE-2019-7484?
CVE-2019-7484 has a severity level of medium (6.5).
4
How can an attacker exploit CVE-2019-7484?
An attacker can exploit CVE-2019-7484 by using SQL injection to gain read-only access to unauthorized resources.
5
Is the SonicWall SMA 100 device vulnerable to CVE-2019-7484?
No, the SonicWall SMA 100 device is not vulnerable to CVE-2019-7484.