Impact
Improper Control of Generation of Code, also known as code injection, is present in the SonicWall Email Security appliance. An attacker who has authenticated access to the restricted command-line interface can inject arbitrary operating system commands that are executed with root privileges through the netmask configuration. This flaw gives the attacker full control of the underlying host, allowing compromise, data exfiltration or pivoting to other systems on the network.
Affected Systems
SonicWall Email Security appliance
Risk and Exploitability
The CVSS base score of 7.8 indicates significant severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available. Because the flaw requires an authenticated session on the restricted CLI, the attack vector is local to the appliance, but once achieved, arbitrary OS commands run as root can lead to complete system compromise. Attackers could leverage the root privileges to install backdoors, exfiltrate data, or pivot to other network assets. Efforts to exploit this flaw are likely to be straightforward once privileged access is obtained, making the risk high for environments that expose the restricted CLI or lack proper network segmentation.
OpenCVE Enrichment