Junglewise Threat Intelligence

CVE-2019-7481: SonicWall SMA100 SQL Injection Vulnerability

CVE-2019-7481 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: SonicWall SMA100. Vendors: SonicWall.

Executive brief

SonicWall SMA100 contains a SQL injection vulnerability due to improper neutralization of special elements in SQL commands. An unauthenticated remote attacker can exploit this to gain unauthorized read-only access to sensitive resources.

Affected products

  • SonicWall SMA 100 firmware 9.0.0.3 and earlier

Timeline

  • 2019-12-17: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild

Related threats