SonicWall SMA1000
cpe:2.3:h:sonicwall:sma1000:*:*:*:*:*:*:*, +1 more
- <= 12.4.3-02804
This vulnerability is being actively exploited in the wild.
A pre-authentication vulnerability allowing deserialization of untrusted data has been identified in the SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC). Under specific conditions, this vulnerability could enable a remote, unauthenticated attacker to execute arbitrary operating system commands. The issue affects SMA1000 versions through 12.4.3-02804 (platform-hotfix).
Exploitation of this vulnerability could lead to unauthorized remote execution of operating system commands on the affected appliance.
Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-02854 (platform-hotfix) or higher. To minimize potential impact, restrict access to the Appliance Management Console and Central Management Console from untrusted sources. Consult the SMA1000 Administration Guide for best practices on securing the appliance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.