SonicWall SMA1000
cpe:2.3:h:sonicwall:sma1000:*:*:*:*:*:*:*, +1 more
- <= 12.4.3-03093
- <= 12.5.0-02002
This vulnerability is being actively exploited in the wild.
A local privilege escalation vulnerability has been identified in the SonicWall SMA1000 appliance management console. This vulnerability arises from insufficient authorization, allowing unauthorized users to gain elevated privileges.
Exploitation of this vulnerability could lead to unauthorized privilege escalation within the appliance management console.
Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-03245 (platform-hotfix) or 12.5.0-02283 (platform-hotfix). The latest platform-hotfix can be downloaded from mysonicwall.com. As a workaround, restrict access to the Appliance Management Console (AMC) by allowing SSH access only via VPN or specific admin IPs, and disable the SSL VPN management interface and SSH access from the public internet.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.