CVE-2026-0204
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.5.5.2-28n |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Nsa 2650 | All versions |
Sonicwall Nsa 3600 | All versions |
Sonicwall Nsa 3650 | All versions |
Sonicwall Nsa 4600 | All versions |
Sonicwall Nsa 4650 | All versions |
Sonicwall Nsa 5600 | All versions |
Sonicwall Nsa 5650 | All versions |
Sonicwall Nsa 6600 | All versions |
Sonicwall Nsa 6650 | All versions |
Sonicwall Sm 9200 | All versions |
Sonicwall Sm 9250 | All versions |
Sonicwall Sm 9400 | All versions |
Sonicwall Sm 9450 | All versions |
Sonicwall Sm 9600 | All versions |
Sonicwall Sm 9650 | All versions |
Sonicwall Soho 250 | All versions |
Sonicwall Soho 250w | All versions |
Sonicwall Sohow | All versions |
Sonicwall Tz 300 | All versions |
Sonicwall Tz 300p | All versions |
Sonicwall Tz 300w | All versions |
Sonicwall Tz 350 | All versions |
Sonicwall Tz 350w | All versions |
Sonicwall Tz 400 | All versions |
Sonicwall Tz 400w | All versions |
Sonicwall Tz 500 | All versions |
Sonicwall Tz 500w | All versions |
Sonicwall Tz 600 | All versions |
Sonicwall Tz 600p | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.0.0.0 to 7.0.1-5169 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Nsa 2700 | All versions |
Sonicwall Nsa 3700 | All versions |
Sonicwall Nsa 4700 | All versions |
Sonicwall Nsa 5700 | All versions |
Sonicwall Nsa 6700 | All versions |
Sonicwall Nssp 10700 | All versions |
Sonicwall Nssp 11700 | All versions |
Sonicwall Nssp 13700 | All versions |
Sonicwall Nssp 15700 | All versions |
Sonicwall Nsv 270 | All versions |
Sonicwall Nsv 470 | All versions |
Sonicwall Nsv 870 | All versions |
Sonicwall Tz270 | All versions |
Sonicwall Tz270w | All versions |
Sonicwall Tz370 | All versions |
Sonicwall Tz370w | All versions |
Sonicwall Tz470 | All versions |
Sonicwall Tz470w | All versions |
Sonicwall Tz570 | All versions |
Sonicwall Tz570p | All versions |
Sonicwall Tz570w | All versions |
Sonicwall Tz670 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.0.0-8035 to 8.2.0-8009 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Nsa 2800 | All versions |
Sonicwall Nsa 3800 | All versions |
Sonicwall Nsa 4800 | All versions |
Sonicwall Nsa 5800 | All versions |
Sonicwall Tz280 | All versions |
Sonicwall Tz280w | All versions |
Sonicwall Tz380 | All versions |
Sonicwall Tz380w | All versions |
Sonicwall Tz480 | All versions |
Sonicwall Tz580 | All versions |
Sonicwall Tz680 | All versions |
Sonicwall Tz80 | All versions |
Related CWEs
CWE-1390
Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References (1)
Source: PSIRT@sonicwall.com
Vendor Advisory
Timeline
No history available yet.