ZeroHour
CyberScooppublished ()ingested @gregotto

SonicWall pushes urgent patch for its SMA appliance

criticalVulnerability exploited in the wildimportance 60CVE-2025-23006

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-23006
Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

9.823% KEV ransomware
  • SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed
Full article494 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The flaw has a severity rating of 9.8 out of 10, and a patch has been made available.

Listen to this article

0:00

Learn more.

(Getty Images)

A critical security flaw has been identified and potentially exploited in SonicWall’s Secure Mobile Access (SMA) 1000 series appliances, sparking significant concern among cybersecurity experts and users worldwide. 

The vulnerability, registered as CVE-2025-23006, allows remote, unauthenticated attackers to execute arbitrary operating system commands under certain conditions. The issue specifically impacts the Appliance Management Console (AMC) and Central Management Console (CMC) used widely in enterprise and government networks for administrative functions.

SonicWall issued a warning Wednesday saying the flaw has a severity rating of 9.8 out of 10 by the Common Vulnerability Scoring System (CVSS), and may have been exploited by malicious actors. Microsoft’s Threat Intelligence Center is credited with uncovering the flaw, although it remains unclear when the exploitation might have commenced. Despite this, SonicWall’s advisory urges all SMA1000 users to upgrade immediately to the patched software version to prevent potential security breaches.

SonicWall’s products provide secure remote access for a wide swath of organizations, often serving managed security service providers (MSSPs), enterprises, and government agencies. 

While SonicWall has confirmed that its Firewall and SMA100 series — geared toward small to medium-sized businesses — remain unaffected by this vulnerability, the company advises proactive measures, such as restrictively managing console access as per its security best practices. 

Germany’s CERT-Bund has also issued advisories, echoing the urgency for immediate patch implementation. A search on Shodan, a search engine for internet-connected devices, indicates that approximately 2,380 SMA1000 devices currently have online exposure.

Further directions on how to secure SMA appliances can be found on SonicWall’s website.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sonicwall-sma-zero-day-patch/