EXPOSURES › CVE-2019-7483
CVE-2019-7483
HIGH ⌖ ON CISA KEV · EXPLOITEDSonicWall SMA100 unauthenticated directory traversal flaw lets attackers probe for files on the server.
An unauthenticated directory traversal vulnerability in the handleWAFRedirect CGI of the SonicWall SMA100 allows attackers to test for the presence of files on the server. This exposes sensitive data and violates CMMC/NIST 800-171 requirements for protecting information systems. DIB organizations should ensure all SonicWall SMA100 devices are patched or replaced to prevent data exfiltration and compliance failures.
Shame score — An unauthenticated directory traversal flaw in a widely deployed firewall product that was actively exploited in the wild, indicating a lack of timely patching and basic access controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.