Vulnerability record · CVE-2019-7481 · published 17 December 2019
CVE-2019-7481: SonicWall SMA100 SQL injection allows unauthenticated read access
Sonicwall · Sma 100 Firmware
SonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources they are not authorized to access. The vulnerability is network-reachable with no privileges or user interaction required, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Description
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, network-reachable, listed in CISA KEV with known ransomware use, and has an EPSS score near 1.0, making exploitation highly likely and impactful.
What it is
SonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources they are not authorized to access. The vulnerability is network-reachable with no privileges or user interaction required, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Impact
An attacker gains read-only access to unauthorized data on the SMA100 appliance. The CVSS vector shows high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network via the SMA100 interface with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed SMA100 management or portal endpoint is a potential entry point.
Exploitation
CISA added this to the KEV catalog on 2021-11-03 with a 2022-05-03 remediation due date and flags known ransomware campaign use; EPSS probability is 0.99906 (99.966th percentile), indicating very high likelihood of exploitation activity.
What to do
- Upgrade SMA100 firmware to a version later than 9.0.0.3 per the SonicWall advisory SNWLID-2019-0016.
- If patching cannot be done immediately, restrict network access to SMA100 interfaces to trusted sources and disable unnecessary exposure to the internet.
- Monitor and review SMA100 logs for anomalous or unexpected query activity from unauthenticated sessions.
- Verify remediation against the CISA KEV required action and track completion against the 2022-05-03 due date if still outstanding.
Detection
- Review SMA100 appliance logs for SQL error messages, malformed query strings, or unusual database access patterns.
- Alert on unauthenticated requests to SMA100 endpoints that return data outside normal portal behavior.
- Correlate network traffic to SMA100 with known SQL injection payload signatures in HTTP parameters.
- Audit for unexpected read access to configuration or user data by sessions lacking valid authentication.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7481 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall SMA100 SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0016 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0016 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7481 | US Government Resource |
Track CVE-2019-7481 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7481), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.