IT

Tracker / CVE-2019-7487

CVE-2019-7487

High 7.8

Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

Affected products and versions

sonicwall sonicos · … → 6.5.3.3
sonicwall sonicos_sslvpn_nacagent

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References