Sonicwall

Sma1000

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS -
  • Veröffentlicht 07.10.2026 13:16:31
  • Zuletzt bearbeitet 07.10.2026 15:16:56

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store ...

Medienbericht
  • EPSS -
  • Veröffentlicht 07.10.2026 13:12:25
  • Zuletzt bearbeitet 07.10.2026 15:16:56

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.

Medienbericht
  • EPSS -
  • Veröffentlicht 07.10.2026 13:09:04
  • Zuletzt bearbeitet 07.10.2026 15:16:55

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated att...

Medienbericht
  • EPSS -
  • Veröffentlicht 07.10.2026 13:07:13
  • Zuletzt bearbeitet 07.10.2026 16:17:32

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct th...

Warnung Medienbericht
  • EPSS 1.63%
  • Veröffentlicht 01.09.2026 21:28:50
  • Zuletzt bearbeitet 21.09.2026 14:17:21

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a...

Warnung Medienbericht
  • EPSS 0.71%
  • Veröffentlicht 01.09.2026 21:25:45
  • Zuletzt bearbeitet 03.09.2026 13:06:16

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sen...

Warnung Medienbericht
  • EPSS 76.35%
  • Veröffentlicht 14.07.2026 19:43:03
  • Zuletzt bearbeitet 16.07.2026 05:16:18

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as...

Warnung Medienbericht
  • EPSS 74.22%
  • Veröffentlicht 14.07.2026 19:39:34
  • Zuletzt bearbeitet 16.07.2026 05:16:18

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

  • EPSS 0.42%
  • Veröffentlicht 09.04.2026 14:27:29
  • Zuletzt bearbeitet 14.05.2026 19:33:35

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

  • EPSS 0.6%
  • Veröffentlicht 09.04.2026 14:25:41
  • Zuletzt bearbeitet 14.05.2026 19:37:22

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.