Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

SonicWall SMA1000 Appliance Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in the SonicWall SMA1000 appliance management console. This vulnerability arises from insufficient authorization, allowing unauthorized users to gain elevated privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation within the appliance management console.

Remediation

Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-03245 (platform-hotfix) or 12.5.0-02283 (platform-hotfix). The latest platform-hotfix can be downloaded from mysonicwall.com. As a workaround, restrict access to the Appliance Management Console (AMC) by allowing SSH access only via VPN or specific admin IPs, and disable the SSL VPN management interface and SSH access from the public internet.

Added: Dec 18, 2025, 11:17 AM
Updated: Dec 18, 2025, 5:39 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
5.7
remediation
7.9
relevance
1.4
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.