CVE-2018-9867: SonicWall SonicOS

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

Affected products

  • SonicWall SonicOS: from 5.0.0.0, up to and including 5.9.1.10; version 6.0.5.3-86o only; version 6.2.7.3 only; version 6.2.7.8 only; version 6.4.0.0 only; version 6.5.1.3 only; …
  • SonicWall Sonicosv: version 6.5.0.2-8v_rc363 only; version 6.5.0.2.8v_rc366 only; version 6.5.0.2.8v_rc367 only; version 6.5.0.2.8v_rc368 only

Published 2019-02-19. Last modified 2026-06-17.