Impact
The vulnerability in SonicOS is an Improper Neutralization of HTTP Headers for Scripting Syntax flaw, allowing a remote attacker to alter the Host header. By manipulating this header, an attacker can redirect users of the firewall's management interface to arbitrary web domains. This can lead to phishing attacks or credential theft, compromising management confidentiality and potentially allowing an attacker to execute further intrusions.
Affected Systems
The affected vendor is SonicWall, specifically the SonicOS operating system. No specific product versions are identified in the available data, so all deployed SonicOS firmware could be vulnerable until a vendor fix is released.
Risk and Exploitability
The CVSS score is not disclosed and the EPSS score is unavailable, but the vulnerability can be exploited remotely via HTTP requests that target the management interface. While it does not directly grant code execution, it creates a high‑risk social‑engineering vector that could enable credential theft. The issue is not listed in CISA's KEV catalog. Because the attack requires access to the management web UI, it is most effective against firewalls exposed to untrusted networks.
OpenCVE Enrichment