Showing 4 vulnerabilities on this page for SonicWall SMA1000

Signals CISA KEV Ransomware Nuclei
SonicWall vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SonicWall SMA1000 LFI

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

CWE-22Jan 19, 20231 related artifact
CVSS7.5v3.1EPSS72.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.

CWE-284CWE-862May 13, 2022
CVSS9.8v3.1EPSS7.59%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.

CWE-601May 13, 2022
CVSS6.1v3.1EPSS8.87%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

CWE-321CWE-798May 13, 2022
CVSS7.5v3.1EPSS4.64%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX