CVE-2019-7486: Code Injection
Published Dec 19, 2019
·Updated
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
Affected Software
2 affected components
SonicWall Sma 100 Firmware<=9.0.0.4
SonicWall SMA 100
Event History
Dec 19, 2019
CVE Published
via MITRE·12:35 AM
Data Sourced
via MITRE·12:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-7486?
CVE-2019-7486 is a code injection vulnerability in the SonicWall SMA100 firmware that allows an authenticated user to execute arbitrary code in the viewcacert CGI script.
2
What software versions are affected by CVE-2019-7486?
CVE-2019-7486 impacts SonicWall SMA100 firmware version 9.0.0.4 and earlier.
3
How severe is CVE-2019-7486?
CVE-2019-7486 has a severity rating of 8.8 (high).
4
How can I fix CVE-2019-7486?
To fix CVE-2019-7486, you should update your SonicWall SMA100 firmware to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2019-7486?
More information about CVE-2019-7486 can be found at the following reference: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0021