Impact
A Zip Slip flaw in the SonicWall Network Security Manager allows an attacker to craft an archive that extracts contents outside the target directory when processed. This path traversal can overwrite or create files in privileged locations, potentially enabling arbitrary code execution or elevating privileges if the server runs with elevated rights.
Affected Systems
SonicWall Network Security Manager (NSM) installations are affected, but specific versions are not listed in the advisory.
Risk and Exploitability
The CVSS score is 9.1, the EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, but these metrics do not diminish the seriousness of the flaw. Because the flaw is triggered via file upload and archive handling, an attacker who can supply a malicious archive to the NSM will have local access to the system’s file system, making the risk high for configurations that expose the upload interface to external users. No additional prerequisites are given, so the attack vector is inferred to be local or remote if the upload path is exposed.
OpenCVE Enrichment