Record summary

CVE-2023-0126 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List12.4.2affected

Nuclei templates

1
ProjectDiscoveryHIGHSonicWall SMA1000 LFICVSS 7.5

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the affected device, potentially leading to unauthorized access or information disclosure.

Remediation

Apply the latest security patches or firmware updates provided by SonicWall to mitigate this vulnerability.

WeaknessesCWE-22
Authorstess
Template tagscve2023cvesonicwalllfisma1000vuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:h:sonicwall:sma1000:-:*:*:*:*:*:*:*
Shodan: title:"Appliance Management Console Login"
FOFA: title="appliance management console login"
Google: intitle:"appliance management console login"

Source: ProjectDiscovery

References

2