First published: Thu Jan 19 2023(Updated: )
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sonicwall Sma1000 Firmware | =12.4.2 | |
SonicWall SMA1000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0126 is a pre-authentication path traversal vulnerability in SonicWall SMA1000 firmware version 12.4.2.
It allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.
The severity of CVE-2023-0126 is high, with a CVSS score of 7.5.
An attacker can exploit CVE-2023-0126 by exploiting the pre-authentication path traversal vulnerability to access sensitive files and directories.
Yes, SonicWall SMA1000 firmware version 12.4.2 is vulnerable to CVE-2023-0126.