SonicWall SMA1000
cpe:2.3:h:sonicwall:sma1000:*:*:*:*:*:*:*, +3 more
- 12.4.3-03245
- 12.4.3-03387
- 12.4.3-03434
- 12.5.0-02283
- 12.5.0-02624
- 12.5.0-02800
This vulnerability is being actively exploited in the wild.
A post-authentication code injection vulnerability has been identified in the SonicWall SMA1000 Appliance Management Console (AMC). Under specific conditions, this vulnerability could allow a remote authenticated attacker with administrative privileges to execute arbitrary operating system commands.
Exploitation of this vulnerability could lead to unauthorized execution of operating system commands with administrative privileges on the affected appliance.
Users are advised to upgrade to version 12.4.3-03453 (platform-hotfix) or 12.5.0-02835 (platform-hotfix) and higher. The latest platform-hotfix is available for download on mysonicwall.com.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.