Executive brief
An unauthenticated directory traversal vulnerability in the handleWAFRedirect CGI component of SonicWall SMA100 appliances allows remote attackers to test for the presence of files on the server. This can be used to disclose sensitive information about the file system structure.
Affected products
- SonicWall SMA 100 Firmware up to and including 9.0.0.3
Timeline
- 2019-12-18: disclosed: NVD Published Date
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-18: other: CISA Due Date for remediation