CVE-2025-23006
Description
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Summary dbcve.org
A pre-authentication deserialization vulnerability exists in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC). An unauthenticated remote attacker can send specially crafted serialized data to the affected interfaces, which when deserialized will execute arbitrary operating system commands on the underlying host.
Mitigation
Apply vendor-provided security patches for SMA1000 AMC and CMC when released. As an interim control, restrict network access to management interfaces via firewall/rules and consider deploying WAF rules to detect deserialization attack patterns.