SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Summary

SonicWall has issued hotfixes for four vulnerabilities affecting its SMA1000 appliances, which provide remote access to corporate networks. The most critical flaw is a pre-authentication SSRF vulnerability with a CVSS score of 10.0, allowing unauthenticated attackers to send requests through the appliance to internal functions.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to access internal network functions, posing a significant risk to organizations using SonicWall SMA1000 appliances.

Severity

10.0 Critical

The vulnerability is rated CVSS 10.0 due to its 'Critical' severity, specifically its pre-authentication nature and Server-Side Request Forgery (SSRF) capabilities, which allow attackers to bypass authentication and interact with internal network resources.

Defender Context

Defenders should prioritize patching SonicWall SMA1000 appliances immediately, as this critical vulnerability allows unauthenticated attackers to compromise internal network access. Organizations should also review their network segmentation and access controls for remote access solutions to mitigate the impact of similar vulnerabilities.

Read Full Story →