Security Notice: Pre-Authentication Path Traversal Vulnerability in SMA 1000 12.4.2
SonicWall PSIRT has confirmed a pre-authentication path traversal vulnerability in specific Secure Mobile Access (SMA) 1000 Series firmware versions. This vulnerability potentially allows an unauthenticated attacker to access arbitrary files and directories stored in the SMA 1000 appliance.
SonicWall PSIRT is not aware of active exploitation against this vulnerability in the wild, nor has a proof of concept (POC) been made public.
OVERVIEW
•
|
Advisory ID: SNWLID-2023-0001
|
•
|
Product(s): SMA 1000 Series (includes SMA 6200, 6210, 7200, 7210, 8200v)
|
•
|
Impacted Version(s): 12.4.2 only
|
•
|
Fixed Version(s): 12.4.2-05352
|
•
|
CVSS: 7.5 (High)
|
•
|
Exploitation: None observed.
|
•
|
Notes: All other SMA 1000 firmware, including version 12.4.1, are NOT impacted by this vulnerability. No action is required for these organizations.
|
|