SonicWall SMA1000
cpe:2.3:h:sonicwall:sma1000:*:*:*:*:*:*:*, +1 more
- <= 12.4.3-03245
- <= 12.5.0-02283
A SQL injection vulnerability has been identified in SonicWall SMA1000 series appliances, specifically in versions 12.4.3-03245 and earlier, as well as 12.5.0-02283 and earlier. This vulnerability allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a user to gain primary administrator rights.
Users are advised to upgrade to SonicWall SMA1000 version 12.4.3-03387 or higher, or version 12.5.0-02624 or higher. The latest platform-hotfix is available for download on mysonicwall.com.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.