← לוח פגיעויות

CVE-2025-23006

קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
SonicWall SMA1000 Appliances Deserialization Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
23% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-502

מוצרים מושפעים

sonicwall: sma8200v; sonicwall: sma6200 firmware; sonicwall: sma6200; sonicwall: sma6210 firmware; sonicwall: sma6210; sonicwall: sma7200 firmware; sonicwall: sma7200; sonicwall: sma7210 firmware; sonicwall: sma7210; sonicwall: sra ex6000 firmware; sonicwall: sra ex6000; sonicwall: sra ex7000 firmware; sonicwall: sra ex7000; sonicwall: sra ex9000 firmware; sonicwall: sra ex9000

קישורים