CVE-2025-2170: SSRF
Published Apr 30, 2025
·Updated
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.
Affected Software
3 affected components
SMA SMA1000 Appliance
All of the following
SonicWall Sma1000 Firmware<12.4.3-02925
SonicWall SMA1000
Event History
Apr 30, 2025
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2170?
CVE-2025-2170 is classified as a high severity Server-side request forgery (SSRF) vulnerability.
2
How do I fix CVE-2025-2170?
To fix CVE-2025-2170, update the SMA1000 Appliance to the latest version provided by the vendor.
3
Who is affected by CVE-2025-2170?
CVE-2025-2170 affects users of the SMA1000 Appliance who use the Work Place interface.
4
What type of vulnerability is CVE-2025-2170?
CVE-2025-2170 is a Server-side request forgery (SSRF) vulnerability.
5
Can CVE-2025-2170 be exploited selectively?
Yes, CVE-2025-2170 can be exploited by a remote unauthenticated attacker under specific conditions.