CVE-2019-7488
Status: ModifiedCritical (9.8)—
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.89%
- Percentile among all scored CVEs: 79
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-255
- CWE-521
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-7488",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "PSIRT@sonicwall.com",
"affectedData": [
{
"vendor": "SonicWall",
"product": "Email Security Appliance",
"versions": [
{
"status": "affected",
"version": "10.0.2 and earlier"
}
]
}
]
}
],
"published": "2019-12-23T22:15:11.407",
"references": [
{
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0014",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT@sonicwall.com"
},
{
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0014",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "PSIRT@sonicwall.com",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-521"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier."
},
{
"lang": "es",
"value": "Una contraseña predeterminada débil causa vulnerabilidad en el dispositivo SonicWall Email Security, lo que conlleva al atacante a conseguir acceso a la base de datos del dispositivo. Esta vulnerabilidad afectó a Email Security Appliance versión 10.0.2 y anteriores."
}
],
"lastModified": "2026-06-17T02:40:39.617",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:email_security_appliance:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2B88C2D-D8CC-43B3-9800-99AF1298AEE3",
"versionEndIncluding": "10.0.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT@sonicwall.com"
}