In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Sonicwall Sonicos | — | Update SonicWall SonicOS to version 6.0.5.3-90o or laterUpdate SonicWall SonicOS to version 6.5.0.2-8v-37-484 or laterUpdate SonicWall SonicOS to version 6.2.7.4 or laterUpdate SonicWall SonicOS to version 6.4.1.0 or laterUpdate SonicWall SonicOS to version 6.5.3.2 or laterUpdate SonicWall SonicOS to version 6.5.0.2-8v-37-489 or laterUpdate SonicWall SonicOS to version 6.5.0.2-8v-37-481 or laterUpdate SonicWall SonicOS to version 6.5.1.4 or laterUpdate SonicWall SonicOS to version 6.2.7.10 or laterUpdate SonicWall SonicOS to version 6.5.1.9 or laterUpdate SonicWall SonicOS to version 5.9.1.12 or laterUpdate SonicWall SonicOS to version 6.5.2.3 or laterUpdate SonicWall SonicOS to version 6.5.0.2-8v-37-485 or later | May 21, 2026 | Feb 15, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub