LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-7481: SonicWall SMA100 SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-7481 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

CVE-2019-7481 is a SQL injection vulnerability in SonicWall SMA100 appliances. An unauthenticated attacker can exploit it to obtain read-only access to unauthorized resources on the device. Because this weakness has been tied to known ransomware activity, organizations running SMA100 should treat it as a priority for inventory, patching, and monitoring.

Public detail is limited to the CISA description and the CWE classification; confirm exact affected builds, fixed releases, and any configuration prerequisites directly against the vendor advisory before acting.

How it works

The flaw belongs to CWE-89 (SQL injection). In products of this class, user-supplied input reaches a database query without proper parameterization or sanitization. An unauthenticated remote attacker can craft requests that alter the intended SQL logic, allowing them to read data they should not be able to access.

According to the CISA summary, successful abuse yields read-only access to unauthorized resources on the SMA100. No further exploit mechanics, payloads, or privilege-escalation paths are provided in the given facts; treat any additional technical claims as unverified until confirmed in the vendor advisory or reliable forensic reporting.

Am I affected? How to find it in your systems

SonicWall SMA100 devices are typically deployed as secure remote-access or SSL-VPN gateways, often at the network edge or in DMZ segments that terminate external user connections. Inventory every appliance that provides SMA100 functionality, including virtual and hardware instances, management interfaces, and any high-availability pairs.

How to remediate

Patch first. Apply the updates specified by SonicWall for the SMA100 exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; do not rely on version guesses or third-party summaries.

If you can't patch immediately

Implement compensating controls while you arrange the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with documented ransomware use, frequently precede data theft or encryption events. If logs or external notifications suggest your SMA100 was targeted, preserve forensic images, review access logs for unauthorized reads, and follow your incident-response plan for credential reset and containment. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in prior compromises.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SMA100
WeaknessCWE-89
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities