In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0017 | Vendor Advisory |
https://www.tenable.com/security/research/tra-2019-08 | Third Party Advisory |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0017 | Vendor Advisory |
https://www.tenable.com/security/research/tra-2019-08 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0017 - Vendor Advisory | |
References | () https://www.tenable.com/security/research/tra-2019-08 - Third Party Advisory |
Information
Published : 2019-02-19 21:29
Updated : 2024-11-21 04:15
NVD link : CVE-2018-9867
Mitre link : CVE-2018-9867
CVE.ORG link : CVE-2018-9867
JSON object : View
Products Affected
sonicwall
- sonicos
- sonicosv