SQL Injection Vulnerability in GMS by SonicWall
CVE-2019-7478

9.8CRITICAL

Key Information:

Vendor
Sonicwall
Status
Vendor
CVE Published:
31 December 2019

Summary

A vulnerability in the GMS platform allows unauthenticated users to exploit SQL injection flaws within the Webservice module. This issue can lead to unauthorized access to sensitive data and manipulation of the underlying database. Affected GMS versions include 8.4, 8.5, 8.6, 8.7, 9.0, and 9.1. Organizations utilizing these versions should implement immediate measures to mitigate potential attacks.

Affected Version(s)

GMS GMS 8.4

GMS GMS 8.5

GMS GMS 8.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.