5.5
CVSSv3

CVE-2018-9867

Published: 19/02/2019 Updated: 16/06/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and previous versions, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sonicwall sonicos

sonicwall sonicos 6.2.7.3

sonicwall sonicos 6.5.1.3

sonicwall sonicos 6.5.2.2

sonicwall sonicos 6.5.3.1

sonicwall sonicos 6.2.7.8

sonicwall sonicos 6.4.0.0

sonicwall sonicos 6.5.1.8

sonicwall sonicos 6.0.5.3-86o

sonicwall sonicosv 6.5.0.2-8v_rc363

sonicwall sonicosv 6.5.0.2.8v_rc367

sonicwall sonicosv 6.5.0.2.8v_rc368

sonicwall sonicosv 6.5.0.2.8v_rc366