PT-2025-20282 · Sma100 · Sma100

Published

2025-05-07

·

Updated

2025-07-18

·

CVE-2025-32820

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SMA100 versions 10.2.1.14-75sv and earlier
Description A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to inject a path traversal sequence, making any directory on the SMA appliance writable.
Recommendations For SMA100 versions 10.2.1.14-75sv and earlier, update to a version later than 10.2.1.14-75sv to resolve the issue. As a temporary workaround, consider restricting access to SSLVPN user privileges to minimize the risk of exploitation. Restrict access to sensitive directories on the SMA appliance to prevent potential path traversal attacks.

Fix

LPE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-06685
CVE-2025-32820

Affected Products

Sma100