Impact
This vulnerability arises from improper control of code generation in the SonicWall Email Security appliance. An authenticated user who can access the SonicWall Email Security restricted command line interface can inject arbitrary operating‑system commands. The injected commands execute with root privileges via SNMP, effectively giving the attacker full control of the device. The weakness is a classic code injection flaw (CWE‑94).
Affected Systems
The affected product is SonicWall Email Security, with all versions that expose the restricted CLI and SNMP interface potentially vulnerable. No specific version ranges are listed in the CNA data, so apply the fix to all deployments that have the CLI enabled.
Risk and Exploitability
The CVSS score of 7.8 reflects a high‑severity flaw. Because the attack requires valid authentication to the restricted CLI, the risk is confined to users or processes that have legitimate access. Once authenticated, the attacker can execute arbitrary commands as root, providing complete compromise of the appliance. The EPSS score is not available and the vulnerability is not noted in CISA KEV, but the high CVSS and the root‑level impact suggest a strong likelihood of exploitation if an attacker gains CLI access. The flaw can be exploited over SNMP, indicating a network‑based attack vector that leverages legitimate administrative channels.
OpenCVE Enrichment