SonicWall Secure Mobile Access (SMA) 1000 series (12.4.2 firmware only) contains a pre-authentication path traversal vulnerability (CVE-2023-0126)
IMPORTANT: SonicWall PSIRT is not aware of active exploitation against this vulnerability in the wild, nor has a proof of concept (POC) been made public.
CVE-2023-0126 is a path traversal vulnerability (CVSS 7.5) that potentially allows an unauthenticated threat actor access to files and directories stored outside the web root directory.
SonicWall engineering published a patch for this vulnerability.