CVE-2025-23006

CRITICAL CISA KEV EPSS 97.4%
Published Jan 23, 20251y ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Critical
Find Similar
Published Jan 23, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Jan 24, 2025 1y ago
KEV Due Feb 14, 2025 501d overdue

Description

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CVSS Details

Base Score
9.8
Exploitability
3.9
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 501d
Added
Jan 24, 2025
Due
Feb 14, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

EPSS Exploit Probability
97.4% percentile
Exploit & Patch Status
Actively Exploited (KEV)
No Patch Available

Weaknesses 1

CWE-502 Deserialization of Untrusted Data Validation

Affected Products 15

VendorProductVersionRange
sonicwallsma8200v* <12.4.3-02854
sonicwallsma6200_firmware* <12.4.3-02854
sonicwallsma6200*any
sonicwallsma6210_firmware* <12.4.3-02854
sonicwallsma6210*any
sonicwallsma7200_firmware* <12.4.3-02854
sonicwallsma7200*any
sonicwallsma7210_firmware* <12.4.3-02854
sonicwallsma7210*any
sonicwallsra_ex6000_firmware* ≤12.4.3-02804
sonicwallsra_ex6000*any
sonicwallsra_ex7000_firmware* ≤12.4.3-02804
sonicwallsra_ex7000*any
sonicwallsra_ex9000_firmware* ≤12.4.3-02804
sonicwallsra_ex9000*any

References 2

  • psirt.global.sonicwall.com https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002
    Vendor Advisory
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23006
    US Government Resource

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.