Impact
The SMA1000 Appliance Management Console contains a post‑authentication code injection flaw (CWE‑94). When an attacker has authenticated as an administrator, the flaw permits arbitrary operating‑system command execution through the console interface. This capability can lead to full compromise of the device’s confidentiality, integrity and availability. The CVSS score of 7.2 reflects the high level of risk associated with this functionality.
Affected Systems
The vulnerability applies to SonicWall SMA1000 devices, specifically the management console component. Because the CNA data does not list specific firmware revisions, and the CPE entries reference various firmware versions of other models, the only definitive scope covered by the CVE is any SMA1000 appliance whose console is accessible over a network. All deployed SMA1000 units with exposed console services should be considered potentially vulnerable until a vendor fix is applied. This inference is made because the official description explicitly mentions the SMA1000 AMC and no version constraints are provided.
Risk and Exploitability
With an EPSS score of 12%, the probability of exploitation is moderately high, and the vulnerability is already listed in the CISA KEV catalog, indicating that attacks have been observed. The attack vector requires an authenticated administrator session, so compromised credentials or insider threat is the primary path. The combination of a 7.2 CVSS score, verified exploitation, and active attacks warrants immediate remediation.
OpenCVE Enrichment