CVE-2026-83548
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SonicWall | SMA1000 | 12.4.3-03453 (platform-hotfix) and older versions | affected |
| SonicWall | SMA1000 | 12.5.0-02835 (platform-hotfix) and older versions | affected |
Weaknesses
- CWE-918: CWE-918 Server-Side request forgery (SSRF)
- CWE-441: CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: active
- Automatable: yes
- Technical Impact: total
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.