
Why it matters
The flaw affects gateways used for remote access and could expose internal functions to unauthenticated requests, making SonicWall's hotfixes operationally relevant to SMA1000 users.
What we know
Confirmed by several sources
- SonicWall released hotfixes for a maximum-severity SSRF flaw affecting SMA1000 appliances or gateways. — The Hacker News, BleepingComputer
Reported by one source
- The flaw could allow an attacker without a login to send requests through the appliance and reach internal functions. — The Hacker News
- SMA1000 gateways provide remote workers access to a company's network and applications. — The Hacker News
- SonicWall said it had no evidence that any of the four flaws addressed by the hotfixes was being exploited. — The Hacker News
Open questions
- Whether the flaw is being exploited; one source reports SonicWall found no evidence, while the other does not address exploitation. — The Hacker News, BleepingComputer
Coverage 2 publishers
-
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
-
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Articles stay on their publishers’ sites; each link opens the original.