← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO AI

SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, Summary: 1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to…

Číst originál na NCSC-FI →

2 zprávy z 2 zdrojů · první · zachyceno CZ · EN/orig

SonicWall NL FI

tg: zranitelnost

CVE v události 4

CVEhodnoceníKEVEPSS
CVE-2026-102255 – – –
CVE-2026-102256 – – –
CVE-2026-102257 – – –
CVE-2026-102258 – – –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Jak se o tom psalo 2

  1. · NCSC-NL NL

    NCSC-2026-0403 [1.00] [M/H] Kwetsbaarheden verholpen in SonicWall SMA1000 Appliance

    SonicWall heeft meerdere kwetsbaarheden verholpen in de SonicWall SMA1000 Appliance. De kwetsbaarheden omvatten een pre-authenticatie Server-Side Request Forgery (SSRF) die ongeauthenticeerde aanvallers in staat stelt om onbevoegde interne verzoeken uit te voeren. Daarnaast is er een post-authenticatie remote code execution kwetsbaarheid via OS command injection. Verder is er een Zip Slip kwetsbaarheid in de management console die het mogelijk maakt om bestanden buiten de bedoelde directories…

  2. · zachyceno · NCSC-FI FI nadpis události

    SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, Summary: 1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to…