Impact
The SMA1000 Appliance Management Console suffers from a post‑authentication improper control of code generation flaw (CWE‑94) that allows an authenticated administrator to inject and run arbitrary operating‑system commands. Because the code generation process is not properly controlled, an attacker can execute any command that the console’s runtime environment permits, giving them full control of the device’s operating system. This leads to complete compromise of confidentiality, integrity, and availability on the affected appliance.
Affected Systems
The vulnerability exists solely in SonicWall’s SMA1000 appliance, specifically its management console component. Only installations that expose the console over the network are at risk; other SonicWall products are not impacted.
Risk and Exploitability
With a CVSS score of 7.2, the issue is classified as high severity. An EPSS score of 76% indicates a very high likelihood of exploitation, and the vulnerability’s listing in CISA’s KEV catalog confirms that attacks have already been observed. Exploitation requires an authenticated administrator account, making insider activity or compromised credentials the primary attack vectors.
OpenCVE Enrichment