ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

SonicWall Urges Immediate Patch for Critical CVE-2025

criticalVulnerability exploited in the wildimportance 60CVE-2025-23006

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-23006
Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

9.823% KEV ransomware
  • SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed
Full article364 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 23, 2025Vulnerability / Network Security

SonicWall is alerting customers of a critical security flaw impacting its Secure Mobile Access (SMA) 1000 Series appliances that it said has been likely exploited in the wild as a zero-day.

The vulnerability, tracked as CVE-2025-23006, is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system.

"Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands," the company said in an advisory.

It's worth noting that CVE-2025-23006 does not affect its Firewall and SMA 100 series products. The flaw has been addressed in version 12.4.3-02854 (platform-hotfix).

SonicWall also said that it has been notified of "possible active exploitation" by unspecified threat actors, necessitating that customers apply the fixes as soon as possible to prevent potential attack attempts.

The company credited the Microsoft Threat Intelligence Center (MSTIC) with discovering and reporting the security shortcoming. When reached for comment, Microsoft told the Hacker News it had nothing to share at this stage.

"To minimize the potential impact of the vulnerability, please ensure that you restrict access to trusted sources for the Appliance Management Console (AMC) and Central Management Console (CMC)," the company recommended.

Update

The U.S. Cybersecurity and Infrastructure Security Agency on Friday confirmed exploitation of CVE-2025-23006, giving federal agencies until February 14, 2025, to patch it.

In a separate security notification, SonicWall said the "vulnerability has been confirmed as being actively exploited in the wild," urging customers to take action immediately. It also said it's in the process of readying information that can be used to verify the integrity of appliances.

The vulnerability has been found to impact the following models: SMA6200, SMA6210, SMA7200, SMA7210, SMA8200v (ESX, KVM, Hyper-V, AWS, Azure), EX6000, EX7000, and EX9000. Besides applying the patch, users are advised to limit access to administrative consoles to trusted internal networks and use a firewall to restrict access to administrative consoles.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/sonicwall-urges-immediate-patch-for.html