First published: Thu Jan 23 2025(Updated: )
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SMA1000 Appliance Management Console | ||
SMA Central Management Console | ||
SonicWall sma8200v | <12.4.3-02854 | |
All of | ||
SonicWall SMA 6200 Firmware | <12.4.3-02854 | |
SonicWall SMA 6200 | ||
All of | ||
SonicWall sma6210 firmware | <12.4.3-02854 | |
SonicWall SMA 6210 | ||
All of | ||
SonicWall SMA 7200 | <12.4.3-02854 | |
SonicWall SMA 7200 | ||
All of | ||
SonicWall SMA 7210 Firmware | <12.4.3-02854 | |
SonicWall sma7210 | ||
All of | ||
SonicWall SRA EX6000 | <=12.4.3-02804 | |
SonicWall SRA EX6000 Firmware | ||
All of | ||
SonicWall SRA EX7000 Firmware | <=12.4.3-02804 | |
SonicWall SRA EX7000 Firmware | ||
All of | ||
SonicWall SRA EX9000 Firmware | <=12.4.3-02804 | |
Sonicwall SRA EX9000 | ||
SonicWall Secure Mobile Access (SMA) 1000 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.