# CVE-2024-12806

## Summary

- **CVE ID:** CVE-2024-12806
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-37
- **Published:** Jan 9, 2025
- **Last Modified:** Mar 13, 2026

## Description

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

## Affected Products

- SonicWall — SonicOS (6.5.4.15-117n and older versions)
- SonicWall — SonicOS (7.0.1-5161 and older version)
- SonicWall — SonicOS (7.1.2-7019)
- SonicWall — SonicOS (8.0.0-8035)

## References

- [CNA](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0004)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.64%
- **EPSS Percentile:** 48.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._