Skip to content
COOEY

EXPOSURES › CVE-2019-7483

CVE-2019-7483

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-7483 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

SonicWall SMA100 unauthenticated directory traversal flaw lets attackers probe for files on the server.

An unauthenticated directory traversal vulnerability in the handleWAFRedirect CGI of the SonicWall SMA100 allows attackers to test for the presence of files on the server. This exposes sensitive data and violates CMMC/NIST 800-171 requirements for protecting information systems. DIB organizations should ensure all SonicWall SMA100 devices are patched or replaced to prevent data exfiltration and compliance failures.

Shame score — An unauthenticated directory traversal flaw in a widely deployed firewall product that was actively exploited in the wild, indicating a lack of timely patching and basic access controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.