CVE-2019-7487

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
19/12/2019
Last modified:
08/01/2020

Description

Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* 6.5.3.3 (including)
cpe:2.3:a:sonicwall:sonicos_sslvpn_nacagent:3.5:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools