Impact
An insufficient certificate validation flaw in the privileged communication workflow of SonicWall GMS allows an attacker who successfully performs a man‑in‑the‑middle (MitM) attack under controlled network conditions to perform unauthorized changes. This flaw can lead to integrity violations and may enable the attacker to modify or inject data through the privileged channel, potentially escalating privileges within the system.
Affected Systems
SonicWall GMS, particularly version 9.5.1 (Build 9510.1044) and earlier releases. The vulnerability is tied to the GMS application’s privileged communication components found in these affected versions.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.3, indicating high severity. Its EPSS score is 0.13%, suggesting a very low probability of exploitation, and it is not listed in CISA’s KEV catalog. Attacking this flaw requires a successful MitM intrusion with controlled network conditions, implying that the attack vector is network‑based and demands some level of network access or interception capability. If exploited, the attacker could alter system configuration or data, compromising confidentiality, integrity, and potentially availability of the GMS deployment.
OpenCVE Enrichment