PatchSiren cyber security CVE debrief
CVE-2019-7481 SonicWall CVE debrief
CVE-2019-7481 is a SonicWall SMA100 SQL injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. CISA marks it as known exploited and notes known ransomware campaign use. The recommended defensive action in the KEV entry is to apply updates per vendor instructions.
- Vendor
- SonicWall
- Product
- SMA100
- CVSS
- HIGH 7.5
- CISA KEV
- Listed
- Original CVE published
- 2021-11-03
- Original CVE updated
- 2021-11-03
- Advisory published
- 2021-11-03
- Advisory updated
- 2021-11-03
Who should care
Organizations running SonicWall SMA100 appliances, especially security operations, infrastructure, and incident response teams responsible for perimeter and remote-access devices.
Technical summary
The available official record identifies this issue as a SQL injection vulnerability affecting SonicWall SMA100. The CISA KEV catalog classifies it as a known exploited vulnerability and associates it with known ransomware campaign use. The KEV entry does not provide exploit mechanics or affected versions, so defenders should rely on vendor remediation guidance and official advisories for scope confirmation.
Defensive priority
High priority. CISA KEV inclusion means the issue is known to be actively exploited and should be treated as urgent for remediation planning.
Recommended defensive actions
- Apply updates per vendor instructions as directed by the CISA KEV catalog.
- Inventory SonicWall SMA100 deployments and confirm which assets are exposed or externally reachable.
- Verify patch status and remediation completion before the CISA KEV due date context or as soon as possible for legacy exposure.
- Review logs and security telemetry for signs of suspicious access around SMA100 devices.
- Coordinate with the vendor and internal incident response teams if remediation cannot be completed immediately.
Evidence notes
Evidence is limited to the supplied official records and links. The source item metadata states: vendorProject SonicWall, product SMA100, vulnerabilityName SonicWall SMA100 SQL Injection Vulnerability, dateAdded 2021-11-03, dueDate 2022-05-03, knownRansomwareCampaignUse Known, requiredAction Apply updates per vendor instructions, and notes linking to the NVD record for CVE-2019-7481. No CVSS score or affected-version details were provided in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-7481 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-7481
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-7481 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-7481
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.