Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

CISA Confirms SonicWall SMA1000 Vulnerability Has Seen Exploitation

CRN by CRN
January 24, 2025
Home News
Share on FacebookShare on Twitter


The U.S. cybersecurity agency says it ‘strongly urges all organizations’ to implement available patches for the critical flaw.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed Friday that a critical vulnerability affecting SonicWall’s SMA1000 Appliance Management Console has seen exploitation in attacks.

The flaw, which also impacts SonicWall’s Central Management Console, was disclosed this week after Microsoft researchers discovered evidence of exploitation. However, SonicWall said in a statement Thursday that partners and customers had not reported any “direct exploitation” of the remote code execution flaw.

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

CRN reached out to SonicWall for further comment Friday. As of this writing, the vendor’s advisory on the issue had not been updated with any new information since Thursday.

CISA said in its advisory Friday that it has added the SonicWall vulnerability (tracked with the identifier CVE-2025-23006) to its catalog of exploited vulnerabilities based on “evidence of active exploitation.”

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the agency said, adding that CISA also “strongly urges all organizations” to prioritize remediation of flaws in the Known Exploited Vulnerabilities Catalog.

The vulnerability can be exploited by a malicious actor to remotely execute code without authentication and has received a “critical” severity rating of 9.8 out 10.0, according to SonicWall.

The flaw impacts versions of the SMA1000 platform up to version 12.4.3-02804 (platform-hotfix). SonicWall has released a patch that fixes the issue.

Researchers at the Microsoft Threat Intelligence Center (MSTIC), according to SonicWall, “discovered evidence of exploitation, prompting a comprehensive code and vulnerability review that led to the discovery of CVE-2025-23006.

“Immediately afterwards, MSTIC informed SonicWall of this discovery,” SonicWall said in its statement Thursday. “MSTIC and SonicWall PSIRT are working closely together to identify and mitigate the vulnerability discussed in this CVE [disclosure].”



Source link

Tags: CyberattacksCybersecuritynetwork securityVulnerabilities
CRN

CRN

Next Post
Dahua Technology schließt sich mit dem WWF zusammen, um die Nachhaltigkeitsbemühungen weltweit auszuweiten

Dahua Technology schließt sich mit dem WWF zusammen, um die Nachhaltigkeitsbemühungen weltweit auszuweiten

Recommended.

MWC25 | Jan Bongaerts, Senior Vice President von YOFC: Förderung des globalen Ausbaus der digitalen Infrastruktur

MWC25 | Jan Bongaerts, Senior Vice President von YOFC: Förderung des globalen Ausbaus der digitalen Infrastruktur

March 9, 2025
Huawei vermeld als leider in de Gartner® Magic Quadrant for Container Management

Huawei vermeld als leider in de Gartner® Magic Quadrant for Container Management

August 18, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio