CVE-2026-4113
Received
Received - Intake
Information Disclosure via Response Discrepancy in SonicWall SMA1000 SSL VPN
Publication date: 2026-04-09
Last updated on: 2026-04-13
Assigner: SonicWALL, Inc.
Description
Description
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sonicwall | sma1000 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-204 | The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere. |