CVE-2019-7483

Confirmed PUBLISHED

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of...

SonicWall · SMA100
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High EPSS 4.0%

At a Glance

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

edge cisa
CVE Published
Dec 19, 2019
Exploitation Reported
Mar 28, 2022
CVSS
7.5 High
EPSS
4.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
SonicWall
SMA100

9.0.0.3 and earlier

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.