In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0017 | Vendor Advisory |
https://www.tenable.com/security/research/tra-2019-08 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-02-19 13:29
Updated : 2022-06-16 09:18
NVD link : CVE-2018-9867
Mitre link : CVE-2018-9867
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
sonicwall
- sonicosv
- sonicos