CVE-2025-23006
Eine Schwachstelle durch Deserialisierung nicht vertrauenswürdiger Daten vor der Authentifizierung wurde in der SMA1000 Appliance Management Console (AMC) und Central Management Console (CMC) identifiziert, die unter bestimmten Bedingungen einem nicht authentifizierten Remote-Angreifer potenziell die Ausführung beliebiger OS-Befehle ermöglichen könnte.
Aktiv ausgenutzt
- Seit dem 24. Jan. 2025 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 14. Feb. 2025 beheben (BOD 22-01)
- Angegriffen 1 Tag bevor die Schwachstelle öffentlich wurde
- In Ransomware-Kampagnen eingesetzt
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 15. Juli 2026 20. Apr. 2026 7. Apr. 2026 5. März 2026 25. Feb. 2026 27. Jan. 2026
CVSS-Score9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-502
Herstellersonicwall
Betroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| sonicwall | sma8200v | < 12.4.3-02854 |
| sonicwall | sma6200 firmware | < 12.4.3-02854 |
| sonicwall | sma6200 | - |
| sonicwall | sma6210 firmware | < 12.4.3-02854 |
| sonicwall | sma6210 | - |
| sonicwall | sma7200 firmware | < 12.4.3-02854 |
| sonicwall | sma7200 | - |
| sonicwall | sma7210 firmware | < 12.4.3-02854 |
| sonicwall | sma7210 | - |
| sonicwall | sra ex6000 firmware | <= 12.4.3-02804 |
| sonicwall | sra ex6000 | - |
| sonicwall | sra ex7000 firmware | <= 12.4.3-02804 |
| sonicwall | sra ex7000 | - |
| sonicwall | sra ex9000 firmware | <= 12.4.3-02804 |
| sonicwall | sra ex9000 | - |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.
