Impact
The flaw allows an external attacker who has not logged in to the SMA1000 Workplace interface to send internal HTTP requests from the device. By exploiting the delegated access control problem (CWE‑441) and the server‑side request forgery mechanism (CWE‑918), the attacker could potentially read or alter protected resources inside the network, giving unauthorized control over certain appliance functions.
Affected Systems
SonicWall SMA1000 Appliance; no version details are publicly listed, so all released models are potentially vulnerable.
Risk and Exploitability
Published metrics are now available: the CVSS score is 10 and the EPSS score is 5%. The vulnerability is listed in CISA KEV, indicating active exploitation. This high severity score, combined with the absence of an authentication requirement and the ability to target internal network services, points to a very high potential impact if the device can reach critical internal systems. The inferred attack vector remains exploitation through the appliance’s internal networking stack, likely from servers or applications that the SMA1000 may already access.
OpenCVE Enrichment