First published: Thu Dec 19 2019(Updated: )
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sonicwall Sma 100 Firmware | <=9.0.0.4 | |
Sonicwall Sma 100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7486 is a code injection vulnerability in the SonicWall SMA100 firmware that allows an authenticated user to execute arbitrary code in the viewcacert CGI script.
CVE-2019-7486 impacts SonicWall SMA100 firmware version 9.0.0.4 and earlier.
CVE-2019-7486 has a severity rating of 8.8 (high).
To fix CVE-2019-7486, you should update your SonicWall SMA100 firmware to a version that is not affected by the vulnerability.
More information about CVE-2019-7486 can be found at the following reference: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0021