CRITICAL

CVE-2025-23006

Sonicwall Sma8200v 2025-01-23 CVSS v3.1
CVSS
9.8
KEV

Description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

Summary dbcve.org

A pre-authentication deserialization vulnerability exists in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC). An unauthenticated remote attacker can send specially crafted serialized data to the affected interfaces, which when deserialized will execute arbitrary operating system commands on the underlying host.

Mitigation

Apply vendor-provided security patches for SMA1000 AMC and CMC when released. As an interim control, restrict network access to management interfaces via firewall/rules and consider deploying WAF rules to detect deserialization attack patterns.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

23.43%
Probability of exploitation in next 30 days
97.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE