Database/Control plane, storage & DevOps
SonicWall SMA1000: pre-auth SSRF via an unintended alternate access path in the Work Place interface
Impact
An unauthenticated request to the Work Place interface reaches functionality that was meant to sit behind authentication, letting an attacker make the appliance issue requests and perform operations on their behalf. SonicWall scores it 10.0 with a scope change, meaning the compromise does not stop at the appliance - the SMA1000 sits at the edge with a route into the internal network, so its outbound request path is a way into management subnets that are otherwise unreachable from the internet. CISA lists it as exploited in the wild. For an operator, the appliance is usually the remote-access path staff use to reach the fleet, so both the exposure and the loss of it during an emergency upgrade land on the same critical piece of equipment.
Who can reach it
Anyone who can reach the SMA1000 Work Place interface over the network, unauthenticated. That interface is normally published to the internet by design.
What to do
Move to the fixed build named in SonicWall advisory SNWLID-2026-0016 - the record does not state a version, so take it from the advisory rather than assuming one. This is an appliance image upgrade and reboot, not a package update: schedule it per node of an HA pair, fail over between them, and expect established sessions to drop. Because the flaw is on the CISA KEV list, treat it as an emergency window and review appliance logs for prior exploitation rather than patching and moving on.
References
Related entries
- Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts): The pipelines frontend hands any unauthenticatedNCVD-2026-042-kubeflow-pipelines-frontend-prox · Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts)Critical
- HTCondor (condor_credd): condor_credd can be told to create or write files as root outsideCVE-2021-25311 · HTCondor (condor_credd)Critical
- RKE / Rancher (k8s control plane): full-cluster-state configmap in kube-system readable by non-adminsCVE-2023-32191 · RKE / Rancher (k8s control plane)Critical
- VMware Aria Automation (missing access control): An authenticated user reaches remote organizations and workflows theyCVE-2023-34063 · VMware Aria Automation (missing access control)Critical
- Cisco Nexus Dashboard Fabric Controller (REST API / web UI): A low-privileged NDFC userCVE-2024-20432 · Cisco Nexus Dashboard Fabric Controller (REST API / web UI)Critical
- Zabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCVE-2024-42327 · ZabbixCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.