Skip to main content

Exploitation could lead to execution of arbitrary OS commands in SonicWall SMA1000 Series Appliances

Summary

Exploitation could lead to execution of arbitrary OS commands in SonicWall SMA1000 Series Appliances 

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

SonicWall has released a security update for a critical vulnerability in Secure Mobile Access (SMA) 1000 Series appliances. This vulnerability impacts the Appliance Management Console (AMC) and Central Management Console (CMC).

SonicWall Secure Mobile Access is described as a unified secure access gateway that provides a Secure Sockets Layer (SSL) virtual private network (VPN), context-aware device authorisation, application level VPN, and advanced authentication with federated single sign-on (SSO) for cloud and on-premises resources.

CVE-2025-23006 is a 'pre-authentication deserialisation of untrusted data' vulnerability with a CVSSv3 score of 9.8, and if exploited could allow a remote, unauthenticated attacker to execute arbitrary OS commands.

Remediation advice

Affected organisations must review SonicWall security advisory SNWLID-2025-0002 and apply the security update to version 12.4.3-02854 (platform-hotfix) and higher.

Remediation steps

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 23 January 2025 2:27 pm