CVE-2019-7483
KEVlargeUnauthenticated Directory Traversal in SonicWall SMA100 handleWAFRedirect CGI
CISA: SonicWall SMA100 Directory Traversal Vulnerability
CVE-2019-7483 is an unauthenticated directory traversal flaw (CWE-22) in the handleWAFRedirect CGI of SonicWall's SMA 100 series SSL-VPN appliances. A remote attacker triggers it by sending a crafted HTTP request to that CGI containing path-traversal sequences, and no credentials or user interaction are required. Per the vulnerability description, the flaw lets an attacker test for the presence of files on the server, and the CVSS 3.1 score of 7.5 rates the confidentiality impact as high, indicating meaningful information exposure. Any organization running a SonicWall SMA 100 appliance, typically deployed as an SMB or branch-office SSL-VPN gateway, is affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2022-03-28, confirming exploitation in the wild, with an EPSS estimate of a 4.0% chance of exploitation in the next 30 days (90th percentile).
What to do: Apply the SMA 100 firmware update per SonicWall's instructions and CISA's required action, and verify patch status on every internet-facing appliance. Until patched, restrict or allowlist access to the appliance's web/SSL-VPN interface and review HTTP logs for suspicious unauthenticated requests to handleWAFRedirect CGI containing traversal sequences.
| SonicWall SMA 100 series (SMA100 firmware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
- Affected
- SonicWall SMA100
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sonicwall
- Products
- sma 100 firmware
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.