First published: Thu Dec 19 2019(Updated: )
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | <=6.5.3.3 | |
Sonicwall Sonicos Sslvpn Nacagent | =3.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7487 is a vulnerability in the SonicOS SSLVPN NACagent 3.5 that allows for code execution if a malicious binary is placed within the parent path.
CVE-2019-7487 has a severity rating of 7.8 (high).
CVE-2019-7487 affects the SonicOS SSLVPN NACagent on the Windows operating system.
Microsoft Windows is not directly affected by CVE-2019-7487, but only when the SonicOS SSLVPN NACagent is installed.
To fix CVE-2019-7487, Sonicwall recommends updating to version 3.5.2 or higher of the SonicOS SSLVPN NACagent.