CVE-2023-0126
SonicWall SMA1000 LFI
Record summary
CVE-2023-0126 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SonicWall SMA1000Browse SonicWall / SonicWall SMA1000 | CVE List | 12.4.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHSonicWall SMA1000 LFICVSS 7.5
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the affected device, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the latest security patches or firmware updates provided by SonicWall to mitigate this vulnerability.
Source: ProjectDiscovery