Showing 3 vulnerabilities on this page for SMA1000 Appliances

Signals CISA KEV Ransomware Nuclei
SonicWall vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SonicWall SMA1000 Appliances Code Injection Vulnerability

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CWE-94Jul 14, 2026
CVSS7.2v3.1EPSS76.3%PoCs3SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CWE-918Jul 14, 20261 related artifact
CVSS10.0v3.1EPSS74.2%PoCs7SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

SonicWall SMA1000 Appliances Deserialization Vulnerability

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CWE-502Jan 23, 2025
CVSS9.8v3.1EPSS23.4%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX