CVE-2019-7479
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
31/12/2019
Last modified:
09/10/2020
Description
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earlier, Gen 6 version 6.2.7.4-32n, 6.5.1.4-4n, 6.5.2.3-4n, 6.5.3.3-3n, 6.2.7.10-3n, 6.4.1.0-3n, 6.5.3.3-3n, 6.5.1.9-4n and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* | 5.9.1.12-4o (including) | |
| cpe:2.3:o:sonicwall:sonicos:6.2.7.4-32n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicos:6.2.7.10-3n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicos:6.4.1.0-3n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicos:6.5.1.4-4n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicos:6.5.1.9-4n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicos:6.5.2.3-4n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicos:6.5.3.3-3n:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicosv:6.5.0.2.8v:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicosv:6.5.0.2.8v:rc363:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicosv:6.5.0.2.8v:rc366:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicosv:6.5.0.2.8v:rc367:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sonicosv:6.5.0.2.8v:rc368:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



