Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
02 Apr 2025, 20:32
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-502 |
27 Jan 2025, 18:41
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sonicwall sra Ex7000
Sonicwall sma6200 Firmware Sonicwall sma7210 Firmware Sonicwall sra Ex9000 Firmware Sonicwall Sonicwall sra Ex7000 Firmware Sonicwall sma6200 Sonicwall sra Ex6000 Sonicwall sma8200v Sonicwall sra Ex6000 Firmware Sonicwall sma7200 Firmware Sonicwall sma7210 Sonicwall sma6210 Sonicwall sma7200 Sonicwall sma6210 Firmware Sonicwall sra Ex9000 |
|
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 - Vendor Advisory | |
CPE | cpe:2.3:o:sonicwall:sra_ex6000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sra_ex7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma6200:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma7200:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sra_ex7000:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sra_ex9000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sra_ex9000:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sra_ex6000:-:*:*:*:*:*:*:* cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
23 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
23 Jan 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-23 12:15
Updated : 2025-04-02 20:32
NVD link : CVE-2025-23006
Mitre link : CVE-2025-23006
JSON object : View
Products Affected
sonicwall
- sma6200
- sra_ex6000
- sma7210_firmware
- sma8200v
- sma6210_firmware
- sma7200
- sra_ex6000_firmware
- sma7210
- sra_ex9000_firmware
- sma6200_firmware
- sra_ex7000_firmware
- sma7200_firmware
- sma6210
- sra_ex7000
- sra_ex9000
CWE
CWE-502
Deserialization of Untrusted Data