CVE-2001-1104 describes a critical vulnerability in SonicWALL SOHO devices, where easily predictable TCP sequence numbers allow remote attackers to spoof or hijack sessions. With a CVSS score of 7.5 (HIGH), this vulnerability is readily exploitable over the network with low attack complexity, potentially leading to unauthorized access, data compromise, and denial of service. While there is no evidence of active exploitation in the wild or readily available Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation. Although an ExploitDB entry for a similar Linux kernel vulnerability exists, it does not directly apply to SonicWALL.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:o:sonicwall:soho_firmware:4.0.0:*:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:o:sonicwall:soho_firmware:5.0.0:*:*:*:*:*:*:* | ||
5.1.5.0CPE matchmatch criteria | cpe:2.3:o:sonicwall:soho_firmware:5.1.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.