First published: Thu Dec 19 2019(Updated: )
Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sonicwall Sma 100 Firmware | <=9.0.0.3 | |
Sonicwall Sma 100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7484 is a vulnerability in SonicWall SMA100 that allows an authenticated user to gain read-only access to unauthorized resources using the viewcacert CGI script.
SMA100 version 9.0.0.3 and earlier are affected by CVE-2019-7484.
CVE-2019-7484 has a severity level of medium (6.5).
An attacker can exploit CVE-2019-7484 by using SQL injection to gain read-only access to unauthorized resources.
No, the SonicWall SMA 100 device is not vulnerable to CVE-2019-7484.