← Back to overview

SonicWall has patched two zero-day vulnerabilities in its SMA1000 Appliance that were actively exploited in the wild. The first vulnerability is a pre-authentication Server-Side Request Forgery (SSRF) in the Work Place interface, allowing unauthenticated remote attackers to perform unauthorized actions. The second vulnerability enables post-authentication remote code execution, allowing attackers with valid credentials to execute arbitrary code remotely. Both vulnerabilities have been confirmed as actively exploited zero-days. The Dutch NCSC (National Cyber Security Centre) urges organizations to follow SonicWall's advisory and apply the available patches immediately. The combination of an unauthenticated SSRF and an authenticated RCE poses a significant risk to organizations using this appliance.

Affected products

  • SonicWall SMA1000 Appliance

Categories

  • Enterprise Applications
  • Network Infrastructure
  • Zero-Day Vulnerabilities