Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- SonicWall / SMA100012.4.3-03453 (platform-hotfix) and older versions – 12.4.3-03453 (platform-hotfix) and older versions
- SonicWall / SMA100012.5.0-02835 (platform-hotfix) and older versions – 12.5.0-02835 (platform-hotfix) and older versions
- SonicWall / sma6210_firmware12.4.3-03526
- SonicWall / sma7210_firmware12.4.3-03526
- SonicWall / sma8200v12.4.3-03526
Exploits & proofs of concept
- nucleiSonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDBby rapid7,DhiyaneshDk
News coverage
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe Hacker News · 18d ago
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainThe Hacker News · 19d ago
References
Updated 9m ago · 8 sources