SonicWall reports exploitation of an SMA1000 pre-authentication proxy path; a separate OS command-injection path requires an administrator.
Affects
SonicWall SMA1000 enterprise SSL-VPN gateways, including physical SMA 6210/7210 appliances and the SMA 8200v virtual appliance.
The first flaw lets an unauthenticated WorkPlace client proxy requests toward internal services, while the second injects commands through the administrator-only Appliance Management Console.
Detail and 2 sources
Chain to watch
Use the pre-authentication WorkPlace path to proxy requests toward internal services.→↓Obtain an administrator session through a route not established in public material.→↓Invoke the Appliance Management Console command-injection endpoint.→↓Public material does not establish that the pre-authentication proxy path supplies the administrator state required by the command-injection endpoint.
Unverified chainObtain a forensic chain or reproducer showing the proxy path reaching an authentication primitive and then the management-console injection.
We do not know whether the proxy path can supply the administrator state needed for command injection, so the public record does not establish unauthenticated code execution.
SonicWall published fixes, but their implementation was not assessed for this brief.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.