Known vulnerabilities in SonicWall SMA 1000 12.4.3-03245
Vendor:
SonicWall
Software:
SonicWall SMA 1000
Version:
12.4.3-03245
Software CPE:
cpe:2.3:h:sonicwall:sma_1000:*:*:*:*:*:*:*:*
Website:
https://www.sonicwall.com/
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137578 - Server-Side Request Forgery (SSRF) CVE-2026-15409 |
CWE-918 | Critical | 12.4.3-03453, 12.5.0-02835 | 15.07.2026 |
SB2026071507 |
||
| #VU137579 - Improper Control of Generation of Code ('Code Injection') CVE-2026-15410 |
CWE-94 | High | 12.4.3-03453, 12.5.0-02835 | 15.07.2026 |
SB2026071507 |
||
| #VU125516 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-4112 |
CWE-89 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU125517 - Observable Response Discrepancy CVE-2026-4113 |
CWE-204 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU125518 - Improper Handling of Unicode Encoding CVE-2026-4114 |
CWE-176 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU125519 - Improper Handling of Unicode Encoding CVE-2026-4116 |
CWE-176 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |