AI Security AI安全 1d ago Updated 15h ago 更新于 15小时前 41

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain 攻击者利用两个SonicWall SMA 1000零日漏洞,可能形成攻击链

SonicWall has released security updates for its Secure Mobile Access (SMA) 1000 series VPN appliances following active zero-day exploitation Two vulnerabilities were discovered internally by SonicWall researchers William Perry and Adam Babis CVE-2026-83548 is a pre-authentication Server-Side Request Forgery (SSRF) flaw with a maximum CVSS score of 10.0 The vulnerabilities affect on-premises VPN gateway appliances used by enterprises for secure remote access Immediate patching is critical given t SonicWall 针对其 Secure Mobile Access (SMA) 1000 系列 VPN 设备发布了安全更新,此前该漏洞已在野外遭到主动利用 两项漏洞由 SonicWall 研究员 William Perry 和 Adam Babis 内部发现 CVE-2026-83548 是一个预认证服务器端请求伪造 (SSRF) 漏洞,CVSS 评分为满分 10.0 这些漏洞影响企业用于安全远程访问的本地 VPN 网关设备 鉴于漏洞已在野外被主动利用,立即修补至关重要

65
Hot 热度
60
Quality 质量
50
Impact 影响力

Analysis 深度分析

TL;DR

  • SonicWall has released security updates for its Secure Mobile Access (SMA) 1000 series VPN appliances following active zero-day exploitation
  • Two vulnerabilities were discovered internally by SonicWall researchers William Perry and Adam Babis
  • CVE-2026-83548 is a pre-authentication Server-Side Request Forgery (SSRF) flaw with a maximum CVSS score of 10.0
  • The vulnerabilities affect on-premises VPN gateway appliances used by enterprises for secure remote access
  • Immediate patching is critical given the active exploitation in the wild

Why It Matters

This is a high-severity, actively exploited zero-day affecting widely deployed VPN infrastructure, making it a critical concern for any organization relying on SonicWall SMA appliances for remote access. Pre-authentication SSRF vulnerabilities of this magnitude can allow unauthenticated attackers to pivot into internal networks, posing severe risk to enterprise security perimeters.

Technical Details

  • CVE-2026-83548: A pre-authentication SSRF vulnerability with a CVSS score of 10.0 (maximum severity), allowing unauthenticated attackers to inject malicious requests that the appliance processes on their behalf
  • Affected Product: SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
  • Discovery: Both vulnerabilities were identified internally by SonicWall security researchers William Perry and Adam Babis
  • Exploitation Status: Actively exploited in zero-day attacks, meaning threat actors are already leveraging these flaws in the wild
  • Vulnerability Class: SSRF (Server-Side Request Forgery) — typically enables attackers to access internal services, exfiltrate data, or enumerate network resources from behind the firewall

Industry Insight

  • Organizations running SonicWall SMA 1000 series appliances should apply the security update immediately and audit logs for signs of prior exploitation, given the active zero-day status
  • This incident reinforces the importance of maintaining up-to-date firmware on perimeter VPN devices, which remain high-value targets for threat actors seeking initial network access
  • The maximum CVSS 10.0 pre-authentication SSRF highlights the ongoing risk of unauthenticated remote code execution paths in enterprise VPN gateways, suggesting vendors and security teams should prioritize zero-trust architectures that limit the blast radius of compromised perimeter devices

摘要

SonicWall 针对其 Secure Mobile Access (SMA) 1000 系列 VPN 设备发布了安全更新,此前该漏洞已在野外遭到主动利用
两项漏洞由 SonicWall 研究员 William Perry 和 Adam Babis 内部发现
CVE-2026-83548 是一个预认证服务器端请求伪造 (SSRF) 漏洞,CVSS 评分为满分 10.0
这些漏洞影响企业用于安全远程访问的本地 VPN 网关设备
鉴于漏洞已在野外被主动利用,立即修补至关重要

深度分析

简要总结

  • SonicWall 针对其 Secure Mobile Access (SMA) 1000 系列 VPN 设备发布了安全更新,此前该漏洞已在野外遭到主动利用
  • 两项漏洞由 SonicWall 研究员 William Perry 和 Adam Babis 内部发现
  • CVE-2026-83548 是一个预认证服务器端请求伪造 (SSRF) 漏洞,CVSS 评分为满分 10.0
  • 这些漏洞影响企业用于安全远程访问的本地 VPN 网关设备
  • 鉴于漏洞已在野外被主动利用,立即修补至关重要

为何重要

这是一起高危且正在被主动利用的零日漏洞,影响广泛部署的 VPN 基础设施,对于任何依赖 SonicWall SMA 设备实现远程访问的组织而言都是关键安全问题。此类严重程度的预认证 SSRF 漏洞可允许未认证的攻击者向内网横向移动,对企业安全边界构成严重威胁。

技术细节

  • CVE-2026-83548:一个 CVSS 评分为 10.0(最高严重性)的预认证 SSRF 漏洞,允许未认证的攻击者注入恶意请求,由设备代为处理
  • 受影响产品:SonicWall Secure Mobile Access (SMA) 1000 系列 VPN 设备
  • 发现情况:两项漏洞均由 SonicWall 安全研究员 William Perry 和 Adam Babis 内部发现
  • 利用状态:已在零日攻击中被主动利用,意味着威胁行为者已在野外利用这些漏洞
  • 漏洞类型:SSRF(服务器端请求伪造)——通常使攻击者能够访问内部服务、窃取数据或从防火墙后方枚举网络资源

行业洞察

  • 鉴于漏洞已在野外被主动利用,运行 SonicWall SMA 1000 系列设备的组织应立即应用安全更新,并审计日志以查找先前利用的迹象

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全