Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

SonicWall Says Exploitation Of SMA1000 Flaw Discovered By Microsoft

CRN by CRN
January 23, 2025
Home News
Share on FacebookShare on Twitter


The cybersecurity vendor says partners and customers have not reported any ‘direct exploitation’ of the critical zero-day vulnerability so far.

SonicWall said Thursday that exploitation of a “critical” zero-day vulnerability in the SMA1000 Appliance Management Console and Central Management Console has been reported by Microsoft threat researchers.

However, partners and customers have not reported any “direct exploitation” of the remote code execution flaw so far, SonicWall said in a statement provided to CRN.

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

The vulnerability (tracked with the identifier CVE-2025-23006) can be exploited by a malicious actor to remotely execute code without authentication, according to SonicWall. It has received a “critical” severity rating of 9.8 out 10.0.

The flaw impacts versions of the SMA1000 platform up to version 12.4.3-02804 (platform-hotfix). SonicWall has released a patch that fixes the issue.

In its security advisory posted online, SonicWall said its threat response team “has been notified of possible active exploitation of the referenced vulnerability by threat actors” — and that the company “strongly advises” upgrades to the fixed version.

However, in its statement Thursday, SonicWall said that “our partners and customers have not reported any direct exploitation to date.”

Researchers at the Microsoft Threat Intelligence Center (MSTIC), according to SonicWall, “discovered evidence of exploitation, prompting a comprehensive code and vulnerability review that led to the discovery of CVE-2025-23006.

“Immediately afterwards, MSTIC informed SonicWall of this discovery,” SonicWall said in its statement Thursday. “MSTIC and SonicWall PSIRT are working closely together to identify and mitigate the vulnerability discussed in this CVE [disclosure].”



Source link

Tags: CyberattacksCybersecuritynetwork securityVulnerabilities
CRN

CRN

Next Post
Climb Global Solutions Taps New CMO, CFO Amid Global Push

Climb Global Solutions Taps New CMO, CFO Amid Global Push

Recommended.

If You Build Them: Databricks To Launch New Data Workflow, AI Agent Development Tools

If You Build Them: Databricks To Launch New Data Workflow, AI Agent Development Tools

June 11, 2025
Stocks making the biggest moves premarket: Walmart, Hewlett Packard Enterprise, Instacart, Broadstone Net Lease and more

Stocks making the biggest moves premarket: Walmart, Hewlett Packard Enterprise, Instacart, Broadstone Net Lease and more

August 21, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio