Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

SonicWall SMA1000 Pre-Authentication Remote Command Execution Vulnerability

Vulnerability

A pre-authentication vulnerability allowing deserialization of untrusted data has been identified in the SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC). Under specific conditions, this vulnerability could enable a remote, unauthenticated attacker to execute arbitrary operating system commands. The issue affects SMA1000 versions through 12.4.3-02804 (platform-hotfix).

Impact

Exploitation of this vulnerability could lead to unauthorized remote execution of operating system commands on the affected appliance.

Remediation

Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-02854 (platform-hotfix) or higher. To minimize potential impact, restrict access to the Appliance Management Console and Central Management Console from untrusted sources. Consult the SMA1000 Administration Guide for best practices on securing the appliance.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.3
remediation
8.3
relevance
0.0
threat
8.5
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.