Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0022 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sonicwall
Published: 2019-12-19T00:35:45
Updated: 2019-12-19T00:35:45
Reserved: 2019-02-06T00:00:00
Link: CVE-2019-7487
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-12-19T01:15:11.133
Modified: 2020-01-08T18:38:30.087
Link: CVE-2019-7487
JSON object: View
Redhat Information
No data.
CWE