Impact
The vulnerability stems from insecure handling of serialized objects in the SonicWall GMS application. An attacker who can interact locally with the affected service can send crafted data that the application deserializes, leading to arbitrary actions that the service is authorized to perform. This weakness is identified as CWE-502, a failure to properly validate or filter data from untrusted sources before deserialization. The potential impact is that an attacker can perform operations beyond intended controls.
Affected Systems
The affected product is SonicWall GMS, specifically version 9.5.1 (build 9510.1044) and all earlier releases. These releases include a service that performs deserialization without proper safeguards.
Risk and Exploitability
The CVSS score is 8.4, and the EPSS value is < 1%. Based on the description, it is inferred that an attacker must communicate directly with the vulnerable service endpoint for exploitation. Because the attack requires local access, it is feasible only when the attacker can reach the network segment where the service is listening. The damage an attacker can cause depends on the privileges that the service runs with. If the service operates with elevated privileges, the impact could be substantial. The vulnerability is not listed in the CISA KEV catalog. The overall risk remains uncertain due to the low EPSS value of < 1%.
OpenCVE Enrichment