The SonicWall Product Security & Incident Response Team (PSIRT) has verified and patched the following vulnerabilities that impact Secure Mobile Access (SMA) 1000 series products (see product list and impacted firmware versions below).
Important: There is no evidence that these vulnerabilities are being exploited in the wild.
Details for each patch can be found in PSIRT Advisory SNWLID-2022-0009.
SonicWall strongly urges that organizations using the SMA 1000 series products upgrade to the latest patch and follow the guidance below.
There are no temporary mitigations. SonicWall urges impacted customers to implement applicable patches as soon as possible.
Impacted Platforms: SMA 1000 Series
SMA 6200, 6210, 7200, 7210, 8000v (ESX, KVM, Hyper-V, AWS, Azure)
Summary | CVSS Score | Impacted Firmware | Fixed Firmware | CVE ID |
Unauthenticated access control bypass | 8.2 (High) | 12.4.0 12.4.1 | 12.4.1-02994 | |
Use of hard-coded cryptographic key | 5.7 (Medium) | 12.4.0 12.4.1 | 12.4.1-02994 | |
URL redirection to an untrusted site (open redirection) | 6.1 (Medium) | 12.4.0 12.4.1 | 12.4.1-02994 |