Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0022 | Vendor Advisory |
Information
Published : 2019-12-18 17:15
Updated : 2020-01-08 10:38
NVD link : CVE-2019-7487
Mitre link : CVE-2019-7487
JSON object : View
CWE
CWE-428
Unquoted Search Path or Element
Products Affected
microsoft
- windows
sonicwall
- sonicos
- sonicos_sslvpn_nacagent