Impact
A post‑authentication stored cross‑site scripting vulnerability allows an attacker who has administrative credentials to store malicious JavaScript in the management console. Once injected, the script can execute in the context of the console, enabling arbitrary code execution, data exfiltration, or manipulation of device settings.
Affected Systems
The affected product is the SonicWall SMA1000 Appliance Management Console. No specific version information is provided.
Risk and Exploitability
The CVSS score is 6.1, indicating medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires administrative authentication and provides a path to arbitrary code execution, the risk to confidentiality, integrity, and availability is high. An attacker who can log in as administrator could leverage this flaw to compromise the console’s operations, potentially extending control to the underlying network appliance.
OpenCVE Enrichment