SonicWall corrige une faille SSRF pré-authentification CVSS 10.0 dans les appliances SMA1000
Titre original : SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Alerte Publié 2026-10-07
SonicWall a publié des correctifs pour quatre vulnérabilités affectant ses appliances SMA1000, utilisées comme passerelles d'accès distant. La faille la plus critique est une vulnérabilité SSRF (Server-Side Request Forgery) permettant à un attaquant non authentifié d'envoyer des requêtes vers des fonctions internes de l'appareil. Cette faille a reçu un score de criticité maximal de 10.0 sur l'échelle CVSS. Si vous administrez l'un de ces équipements, installez immédiatement les correctifs fournis par l'éditeur.
Extrait original (en anglais)
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being