« Volver al listado

CVE-2019-7476

Estado: ModificadaAlta (8.1)—

A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-7476",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@sonicwall.com",
      "affectedData": [
        {
          "vendor": "SonicWall",
          "product": "Global Management System (GMS)",
          "versions": [
            {
              "status": "affected",
              "version": "9.1"
            },
            {
              "status": "affected",
              "version": "9.0"
            },
            {
              "status": "affected",
              "version": "8.7"
            },
            {
              "status": "affected",
              "version": "8.6"
            },
            {
              "status": "affected",
              "version": "8.4"
            },
            {
              "status": "affected",
              "version": "8.3 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-26T21:29:00.487",
  "references": [
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0004",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@sonicwall.com"
    },
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0004",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@sonicwall.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1188"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en SonicWall Global Management System (GMS) permite a un atacante remoto obtener acceso empleando una clave SSH existente. Esta vulnerabilidad afecta las versiones de GMS 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 y anteriores."
    }
  ],
  "lastModified": "2026-06-17T02:40:38.387",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFFEBF80-7249-4CA6-A6C0-6F6329152FF8",
              "versionEndIncluding": "8.3"
            },
            {
              "criteria": "cpe:2.3:a:sonicwall:global_management_system:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD7682E7-0BD5-440C-ABA4-4054D093A57E"
            },
            {
              "criteria": "cpe:2.3:a:sonicwall:global_management_system:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "431CAC0A-9915-4D07-A22D-4D674ACC7DBA"
            },
            {
              "criteria": "cpe:2.3:a:sonicwall:global_management_system:8.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBD3B183-8BA1-4021-882B-C06ED1C39D8B"
            },
            {
              "criteria": "cpe:2.3:a:sonicwall:global_management_system:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8110BA2E-3C68-4C91-BD84-1E2E53AB31AA"
            },
            {
              "criteria": "cpe:2.3:a:sonicwall:global_management_system:9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CCAD1F4-A32A-41FD-B3F6-418625A9179C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT@sonicwall.com"
}