SonicWall SonicOS Vulnerability Allows Unstable Firewall State for Read-Only Admins
CVE-2019-7474
6.5MEDIUM
Summary
A vulnerability exists within SonicWall SonicOS that allows an authenticated read-only administrator to trigger an unstable state in the firewall by downloading certificates with specific extensions. This issue impacts various versions of SonicOS across Gen 5 and Gen 6, as well as SonicOS virtual editions. Organizations utilizing affected versions should investigate potential risks and apply necessary measures to mitigate the impact on their network infrastructure.
Affected Version(s)
SonicOS 5.9.1.10 and earlier
SonicOS 6.2.7.3
SonicOS 6.5.1.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved