← Back to advisories & guidance
January 28, 2025
CERT-EU
Advisory
Summary
An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary code on the affected appliance. The vulnerability CVE-2025-23006 , with a CVSS score of 9.8, is a deserialisation of untrusted data vulnerability in the Appliance Management Console (AMC) and Central Management Console (CMC) of the SonicWall SMA 1000. An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary code and gain control over affected systems. The vulnerability affects all firmware versions of the SMA1000 appliance up to 12.4.3-02804 It is strongly recommended applying updates and check for any suspicious configuration change It is strongly recommended restricting access to the Appliance Management Console (AMC) and Central Management Console (CMC) to only trusted networks [2].
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.