SonicWall Issues Critical Hotfixes for SMA1000 Pre-Authentication SSRF Vulnerability
CVSMA1000 appliances rated 10.0 on CVSS scale; no known wild exploitation but risk remains high for unpatched devices

Key Takeaways
- SonicWall has released hotfixes for four vulnerabilities in SMA1000 appliances, including a critical pre-authentication SSRF flaw rated CVSS 10.0.
- The most serious flaw could allow an attacker without valid credentials to send crafted requests through the appliance and reach internal network functions.
- SonicWall states there is no evidence the flaws are being exploited in the wild at the time of patching.
Related Security News

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software used to accelerate large language model (LLM) servers, allows unauthenticated remote code execution via the ZeroMQ messaging protocol. No fixed version is currently available, prompting advisories to restrict network exposure.


