HomeDefault status
unknown
12.4.3-02676 and earlier versions
affected
Description
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
12.4.3-02676 and earlier versions
Credits
Wenjie Zhong (H4lo) of Webin DBappSecurity Co., Ltd.
References
psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0017