SonicWall issues hotfixes for four SMA1000 flaws, one rated CVSS 10.0
SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access gateways. The most serious is a server-side request forgery bug that could let an attacker without credentials make the appliance send requests and reach internal functions. According to The Hacker News, SonicWall says it has no evidence that any of the four flaws is being exploited.
- SMA1000 gateways give remote workers access to company networks and applications.
- The attacker needs no valid login to exploit the most serious flaw.
- SonicWall rates the SSRF bug the maximum 10.0 on the CVSS scale.
Covered by 4 publishers within 7 hours of the first report.
Reporting4
BleepingComputer SonicWall warns of max severity SSRF flaw in SMA1000 gateways · Sergiu Gatlan
Cyber Security News SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10 · Guru Baran
The Hacker News SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances · info@thehackernews.com (The Hacker News)
Security Affairs SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances · Pierluigi Paganini