Impact
A missing authorization check in the SonicWall Network Security Manager (NSM) On‑Prem Management interface allows a user who has been granted a lower‑privileged Admin role to acquire SuperAdmin privileges. This escalation grants the attacker the authority associated with a SuperAdmin account, enabling full management of the system as permitted by that role.
Affected Systems
SonicWall Network Security Manager (NSM) On‑Prem Management interface. Any deployment of this product that has not yet applied the vendor’s patch for the missing authorization flaw is vulnerable. Version information is not specified in the advisory, so all impacted installations are presumed affected until verified otherwise by the vendor.
Risk and Exploitability
The vulnerability is classified as a missing authorization flaw (CWE‑862). Exploitation requires the attacker to already have access to the management interface as a lower‑privileged Admin. It is inferred that the attack vector involves remote or internal access to the management interface. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the nature of the flaw implies a severe risk if left unpatched. The CVSS score of 9.1 indicates a critical severity.
OpenCVE Enrichment