Impact
A Server‑Side Request Forgery (SSRF) flaw exists within the Work Place interface of SonicWall SMA1000 appliances. The vulnerability, classified as CWE‑918, enables a remote actor who does not need to authenticate to the device to instruct the appliance to send HTTP requests to arbitrary URLs. It is inferred that the flaw could lead to unintended data exfiltration, credential discovery, or other actions from the appliance’s network context.
Affected Systems
SonicWall SMA1000 appliances are affected. No specific firmware versions are listed, so the scope is unclear beyond the existence of the vulnerability.
Risk and Exploitability
The flaw carries a CVSS score of 10, indicating critical severity, and an EPSS score of 84%, reflecting a high likelihood that exploitation attempts are currently in progress. The item is listed in CISA’s KEV catalog, confirming active exploitation in the wild. Attackers exploit it by sending crafted requests to the exposed Work Place interface, which then forwards the request outbound, regardless of the destination headers supplied. No authentication or additional access controls are required, allowing an attacker to trigger the request from any network location that can reach the interface.
OpenCVE Enrichment