Executive brief
SonicWall SMA 1000 series appliances, which provide secure remote access to corporate networks, are affected by a vulnerability that allows attackers to identify valid user credentials. By observing subtle differences in how the system responds to login attempts, an attacker can determine which usernames or passwords are valid. This information can be used to facilitate unauthorized access to the corporate network and sensitive internal data.
Technical details
The vulnerability is classified as CWE-204 (Observable Response Discrepancy) within the SonicWall SMA 1000 series firmware. It occurs when the appliance provides different responses (such as timing differences or error messages) that allow an attacker to distinguish between valid and invalid user credentials. While the CVSS vector indicates high privileges are required, the nature of credential enumeration typically targets the authentication phase. An attacker can exploit this over the network to conduct brute-force or account harvesting attacks. SonicWall has released firmware updates (12.4.3-03387 and 12.5.0-02624) to address the issue.
Affected products
- SonicWall SMA 1000 Series Firmware Versions up to 12.4.3-03387 and 12.5.0 up to 12.5.0-02624
Timeline
- 2026-04-09: disclosed: Initial disclosure by SonicWall
- 2026-04-09: advisory: NVD publication date
- 2026-05-14: patched: NVD updated with specific patched version ranges