poslední zpráva
SPOJENO AI
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...]
SonicWall US IT NL FI
CVE v události 4
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-102255 | – | – | – |
| CVE-2026-102256 | – | – | – |
| CVE-2026-102257 | – | – | – |
| CVE-2026-102258 | – | – | – |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.
Tahle CVE jsem vytáhl z širšího textu článku: CVE-2026-15409, CVE-2026-15410, CVE-2026-83548, CVE-2026-83549. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.
Jak se o tom psalo 4
-
· BleepingComputer US nadpis události
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...]
-
· CSIRT Itálie (ACN) IT
Risolte vulnerabilità in prodotti SonicWall
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 4 vulnerabilità, di cui 1 con gravità "critica" e 2 con gravità "alta", che interessano i modelli 6210, 7210 e 8200v appartenenti alla serie SMA1000. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di eludere dei meccanismi di sicurezza e di eseguire codice arbitrario sui sistemi interessati.
-
· NCSC-NL NL
NCSC-2026-0403 [1.00] [M/H] Kwetsbaarheden verholpen in SonicWall SMA1000 Appliance
SonicWall heeft meerdere kwetsbaarheden verholpen in de SonicWall SMA1000 Appliance. De kwetsbaarheden omvatten een pre-authenticatie Server-Side Request Forgery (SSRF) die ongeauthenticeerde aanvallers in staat stelt om onbevoegde interne verzoeken uit te voeren. Daarnaast is er een post-authenticatie remote code execution kwetsbaarheid via OS command injection. Verder is er een Zip Slip kwetsbaarheid in de management console die het mogelijk maakt om bestanden buiten de bedoelde directories…
-
· zachyceno · NCSC-FI FI
SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, Summary: 1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to…