Executive brief
A pre-authentication deserialization of untrusted data vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) allows remote, unauthenticated attackers to execute arbitrary OS commands. The vulnerability is actively exploited in the wild and affects various SMA and SRA firmware versions.
Affected products
- SonicWall SMA1000 Appliance Management Console (AMC)
- SonicWall Central Management Console (CMC)
- SonicWall SMA 6200 Firmware < 12.4.3-02854
- SonicWall SMA 6210 Firmware < 12.4.3-02854
- SonicWall SMA 7200 Firmware < 12.4.3-02854
- SonicWall SMA 7210 Firmware < 12.4.3-02854
- SonicWall SMA 8200v < 12.4.3-02854
- SonicWall SRA EX6000 Firmware <= 12.4.3-02804
- SonicWall SRA EX7000 Firmware <= 12.4.3-02804
- SonicWall SRA EX9000 Firmware <= 12.4.3-02804
Timeline
- 2025-01-24: disclosed
- 2025-01-24: advisory
- 2025-01-24: kev added: Added to CISA KEV catalog due to active exploitation.