Vulnerability record · CVE-2019-7483 · published 19 December 2019
CVE-2019-7483: SonicWall SMA100 unauthenticated directory traversal in handleWAFRedirect CGI
Sonicwall · Sma 100 Firmware
SonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a user test for the presence of a file on the server, so it is an information-disclosure issue rather than direct code execution. It matters because the endpoint is reachable without credentials and the product is an internet-facing remote access appliance.
Description
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with no authentication required and confirmed exploitation per CISA KEV, though impact is limited to file-presence disclosure.
What it is
SonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a user test for the presence of a file on the server, so it is an information-disclosure issue rather than direct code execution. It matters because the endpoint is reachable without credentials and the product is an internet-facing remote access appliance.
Impact
An attacker can probe the server for the existence of files, gaining reconnaissance information about the appliance. The record does not indicate file contents are read, only that file presence can be tested.
Attack surface
Reached over the network via the handleWAFRedirect CGI on the SMA100 web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
It is listed in CISA KEV (added 2022-03-28), indicating known exploitation in the wild; EPSS 30-day probability is about 4.0 percent (90th percentile). No ransomware campaign use is recorded.
What to do
- Apply the vendor update referenced in SonicWall advisory SNWLID-2019-0018, following CISA's required action.
- Restrict or block external access to the SMA100 management/web interface where operationally possible.
- Monitor and log requests to the handleWAFRedirect CGI endpoint.
- If patching is delayed, place the appliance behind filtering that blocks traversal sequences in request paths.
Detection
- Search web/proxy logs for requests to handleWAFRedirect containing traversal sequences such as ../ or encoded variants.
- Alert on unauthenticated requests to CGI endpoints on SMA100 appliances from unexpected source IPs.
- Correlate repeated file-probing requests from a single source against the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7483 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "SonicWall SMA100 Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0018 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0018 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7483 | US Government Resource |
Track CVE-2019-7483 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7483), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.