A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
CVE ID: CVE-2024-45317
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
Vendor: SonicWall
Product: SMA1000
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 16.74% (scored less or equal to compared to others)
EPSS Date: 2025-04-20 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: true