Impact
An unauthenticated remote code execution flaw has been identified in SonicWall GMS 9.5.1 (build 9510.1044) and all earlier releases; the defect, a Code Injection weakness (CWE‑94), allows a malicious actor to supply a specially crafted ZIP file that exploits a zipslip path‑traversal bug, enabling arbitrary file writes and direct reading of sensitive data on the device, effectively granting full control over the appliance.
Affected Systems
The vulnerability affects SonicWall GMS versions up to and including 9.5.1 build 9510.1044. Any GMS appliance running a release in this range without an applicable patch is therefore vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, while the EPSS score of less than 1 % suggests a low probability of exploitation relative to other threats. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated remote attacker who embeds and uploads a malicious ZIP archive to the vulnerable GMS, triggering the zipslip exploit and achieving arbitrary file writes.
OpenCVE Enrichment