First published: Thu Jan 23 2025(Updated: )
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SMA1000 Appliance Management Console | ||
SMA Central Management Console | ||
SonicWall SSL VPN | ||
SonicWall SMA 8200v | <12.4.3-02854 | |
All of | ||
SonicWall SMA 6200 Firmware | <12.4.3-02854 | |
SonicWall SMA 6200 | ||
All of | ||
SonicWall SMA 6210 | <12.4.3-02854 | |
SonicWall SMA 6210 | ||
All of | ||
SonicWall SMA 7200 | <12.4.3-02854 | |
SonicWall SMA 7200 | ||
All of | ||
SonicWall SMA 7210 Firmware | <12.4.3-02854 | |
SonicWall SMA 7210 | ||
All of | ||
SonicWall SRA EX6000 | <=12.4.3-02804 | |
SonicWall SRA EX6000 | ||
All of | ||
SonicWall SRA EX7000 | <=12.4.3-02804 | |
SonicWall SRA EX7000 | ||
All of | ||
SonicWall SRA EX9000 | <=12.4.3-02804 | |
SonicWall SRA EX9000 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23006 has been classified with a high severity due to its potential to allow remote unauthenticated attackers to execute arbitrary code.
To remediate CVE-2025-23006, it is recommended to update the affected SonicWall SMA1000 Appliance Management Console and Central Management Console to the latest patched version.
CVE-2025-23006 affects SonicWall SMA1000 Appliance Management Console and Central Management Console, along with specific firmware versions for devices like SMA6200, SMA7200, and others.
Yes, CVE-2025-23006 can be exploited by remote attackers without authentication under certain conditions.
CVE-2025-23006 is a pre-authentication deserialization vulnerability involving untrusted data.