Impact
The flaw allows an external attacker who has not logged in to the SMA1000 Workplace interface to send internal HTTP requests from the device. By exploiting the delegated access control problem (CWE‑441) and the server‑side request forgery mechanism (CWE‑918), the attacker could potentially read or alter protected resources inside the network, giving unauthorized control over certain appliance functions.
Affected Systems
SonicWall SMA1000 Appliance; no version details are publicly listed, so all released models are potentially vulnerable.
Risk and Exploitability
Published metrics are absent; the CVSS score and EPSS are not available. The KEV status is known: the vulnerability is not listed in CISA KEV. This lack of quantification makes it difficult to precisely gauge the risk, yet the lack of authentication requirement and the capability to target internal services suggest a moderate to high potential impact if the device can reach critical internal systems. The inferred attack vector is exploitation through the appliance’s internal networking stack, likely from servers or applications that the SMA1000 may already access.
OpenCVE Enrichment