Impact
A Server‑Side Request Forgery vulnerability exists in the SonicWall SMA1000 Appliance Work Place interface. The defect, classified as CWE‑918, lets a remote unauthenticated attacker force the appliance to send HTTP requests to arbitrary URLs.
Affected Systems
All current and legacy installations of the SonicWall SMA1000 appliance are affected. No specific firmware versions are listed in the advisory, so every deployed unit should assume vulnerability until a patch is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 10, indicating critical severity. The EPSS score of 78% indicates a high probability that exploitation attempts are already occurring. It is listed in CISA’s KEV catalog, confirming active exploitation in the wild. Attackers can exploit the flaw remotely without authentication, forcing the appliance to issue outbound HTTP requests to target URLs based on attacker input.
OpenCVE Enrichment