A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical pre-authentication SSRF vulnerability in the SonicWall SMA1000 Appliance WorkPlace interface, rated CVSS 10.0. An unauthenticated remote attacker can exploit an unintended proxy path to reach protected internal functions and perform unauthorized operations without user interaction. Affected firmware includes 12.4.3-03526 and earlier and 12.5.0-02952 and earlier. Fixed releases are platform-hotfix 12.4.3-03670 and later or 12.5.0-03082 and later.
A pre-authentication server-side request forgery vulnerability allows remote unauthenticated attackers to send crafted requests through the Appliance Work Place interface, reach trusted internal endpoints, and perform operations normally restricted to authenticated users or administrators. Affects physical and virtual SMA 1000 models 6210, 7210, and 8200v. Fixed in firmware 12.4.3-03670 and higher, and 12.5.0-03082 and higher. SonicWall reports no evidence of exploitation; the article's suggestion of future exploitation is speculative.
A critical pre-authentication server-side request forgery vulnerability in SonicWall SMA1000, rated CVSS 10.0. An unauthenticated remote attacker could abuse an unintended alternate access path to make the appliance issue requests, reach internal functionality, and perform unauthorized operations. Affected versions are 12.4.3-03526 (platform-hotfix) and older, and 12.5.0-02952 (platform-hotfix) and older. The advisory states that the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog; it does not establish whether exploitation has occurred.
A critical unauthenticated SSRF and unintended proxy vulnerability in SonicWall SMA1000 appliances. An alternate access path lets remote attackers make the appliance issue requests on their behalf, reach internal functionality, and perform unauthorized operations without credentials or user interaction. Affected builds include 12.4.3-03526 and earlier and 12.5.0-02952 and earlier. Fixed platform hotfixes are 12.4.3-03670 and 12.5.0-03082. SonicWall reports no evidence of exploitation, and no public proof of concept is known at the time of writing.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.