In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sonicwall

Published: 2019-02-19T21:00:00

Updated: 2019-04-02T17:20:39

Reserved: 2018-04-09T00:00:00


Link: CVE-2018-9867

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-02-19T21:29:00.320

Modified: 2022-06-16T16:18:55.643


Link: CVE-2018-9867

JSON object: View

cve-icon Redhat Information

No data.