# OWASP Top 10: Server-Side Request Forgery

CVEs whose CWE falls in the OWASP Top 10 (2021) category A10, SSRF.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/enrichment-cwe-owasptop10-2021/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs whose CWE falls in the OWASP Top 10 (2021) category A10, SSRF.

Example 2 of 8 in **Filters › CWE** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `enrichment.cwe.owasptop10_2021` · `operator` `eq`

`enrichment.cwe.owasptop10_2021` is the OWASP Top 10 (2021) category of the CWE.

`eq` matches the exact value `A10 Server-Side Request Forgery (SSRF)`.

In the response, look at `results[].enrichment.cwe[].owasptop10_2021`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `enrichment.cwe.owasptop10_2021` |
| `filters.must[0].type` | body | `eq` |
| `filters.must[0].value` | body | `A10 Server-Side Request Forgery (SSRF)` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "enrichment.cwe.owasptop10_2021",
        "type": "eq",
        "value": "A10 Server-Side Request Forgery (SSRF)"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 3604,
  "results": [
    {
      "id": "CVE-2026-92808",
      "source_identifier": "4760f414-e1ae-4ff1-bdad-c7a9c3538b79",
      "published": "2026-09-16T20:17:49Z",
      "last_modified": "2026-09-18T17:48:19Z",
      "status": "Awaiting Analysis",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server itself.\n\n\n\n\nOne such internal service exposes server configuration and credential material without authentication, relying only on the request originating locally. Because the forged requests originate from the server process, that check is satisfied. An unauthenticated attacker can therefore retrieve stored credentials and use them to obtain an administrative session, resulting in full compromise of the server and all of its services. Altium 365 cloud deployments are not affected, as the affected endpoint is disabled in cloud mode."
        }
      ],
      "references": [
        {
          "url": "https://www.altium.com/platform/security-compliance/security-advisories",
          "source": "4760f414-e1ae-4ff1-bdad-c7a9c3538b79",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": [
          {
            "source": "4760f414-e1ae-4ff1-bdad-c7a9c3538b79",
            "type": "Secondary",
            "cvss_data": {
              "version": "4.0",
              "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "attack_requirements": "NONE",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "vulnerable_system_confidentiality": null,
              "vulnerable_system_integrity": null,
              "vulnerable_system_availability": null,
              "subsequent_system_confidentiality": null,
              "subsequent_system_integrity": null,
              "subsequent_system_availability": null,
              "exploit_maturity": "NOT_DEFINED",
              "confidentiality_requirements": null,
              "integrity_requirements": null,
              "availability_requirements": null,
              "modified_attack_vector": "NOT_DEFINED",
              "modified_attack_complexity": "NOT_DEFINED",
              "modified_attack_requirements": "NOT_DEFINED",
              "modified_privileges_required": "NOT_DEFINED",
              "modified_user_interaction": "NOT_DEFINED",
              "modified_vulnerable_system_confidentiality": null,
              "modified_vulnerable_system_integrity": null,
              "modified_vulnerable_system_availability": null,
              "modified_subsequent_system_confidentiality": null,
              "modified_subsequent_system_integrity": null,
              "modified_subsequent_system_availability": null,
              "safety": null,
              "automatable": null,
              "recovery": null,
              "value_density": "NOT_DEFINED",
              "vulnerability_response_effort": "NOT_DEFINED",
              "provider_urgency": "NOT_DEFINED",
              "base_score": 10.0,
              "base_severity": "CRITICAL"
            }
          }
        ],
        "cvss_metric_v31": null,
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "4760f414-e1ae-4ff1-bdad-c7a9c3538b79",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-306"
            },
            {
              "lang": "en",
              "value": "CWE-918"
            }
          ]
        }
      ],
      "configurations": null,
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 306,
            "owasptop10_2021": "A07 Identification and Authentication Failures",
            "name": "Missing Authentication for Critical Function",
            "description": "The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.",
            "capec_id": [
              12,
              36,
              62,
              166,
              216
            ],
            "scope": [
              "Access Control",
              "Other"
            ],
            "impact": [
              "Gain Privileges or Assume Identity",
              "Varies by Context"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          },
          {
            "id": 918,
            "owasptop10_2021": "A10 Server-Side Request Forgery (SSRF)",
            "name": "Server-Side Request Forgery (SSRF)",
            "description": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.",
            "capec_id": [
              664
            ],
            "scope": [
              "Access Control",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00321,
          "percentile": 0.25197,
          "date": "2026-09-21"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "4.0"
          ],
          "source": "4760f414-e1ae-4ff1-bdad-c7a9c3538b79",
          "type": "Secondary",
          "cvss_data": {
            "version": "4.0",
            "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": "NONE",
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": null,
            "vulnerable_system_integrity": null,
            "vulnerable_system_availability": null,
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": "NOT_DEFINED",
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": "NOT_DEFINED",
            "modified_attack_complexity": "NOT_DEFINED",
            "modified_attack_requirements": "NOT_DEFINED",
            "modified_privileges_required": "NOT_DEFINED",
            "modified_user_interaction": "NOT_DEFINED",
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": "NOT_DEFINED",
            "vulnerability_response_effort": "NOT_DEFINED",
            "provider_urgency": "NOT_DEFINED",
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-83660",
      "source_identifier": "user@adobe.com",
      "published": "2026-09-22T18:17:22Z",
      "last_modified": "2026-09-23T20:42:33Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed."
        }
      ],
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/campaign/apsb26-142.html",
          "source": "user@adobe.com",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@adobe.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "LOW",
              "availability_impact": "LOW",
              "base_score": 9.9,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.3
          },
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@adobe.com",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-918"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*",
                  "match_criteria_id": "372C9136-435C-4501-9FB8-016600591108",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": "7.4.3",
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:adobe:campaign:7.4.4:9400:*:*:classic:*:*:*",
                  "match_criteria_id": "560799AF-A848-47B5-B37C-7B35C8D1B48B",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:adobe:campaign:7.4.4:9401:*:*:classic:*:*:*",
                  "match_criteria_id": "FA9301A1-69C2-470A-9520-E865A32B38BF",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*",
            "vendor": "adobe",
            "product": "campaign",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": "7.4.3",
            "version_end_excluding": null,
            "affected_versions_first": "7.2.1",
            "affected_versions_last": "7.4.3"
          },
          {
            "criteria": "cpe:2.3:a:adobe:campaign:7.4.4:9400:*:*:classic:*:*:*",
            "vendor": "adobe",
            "product": "campaign",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "7.4.4",
            "affected_versions_last": "7.4.4"
          },
          {
            "criteria": "cpe:2.3:a:adobe:campaign:7.4.4:9401:*:*:classic:*:*:*",
            "vendor": "adobe",
            "product": "campaign",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "7.4.4",
            "affected_versions_last": "7.4.4"
          },
          {
            "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
            "vendor": "linux",
            "product": "linux_kernel",
            "product_type": "o",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
            "vendor": "microsoft",
            "product": "windows",
            "product_type": "o",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 918,
            "owasptop10_2021": "A10 Server-Side Request Forgery (SSRF)",
            "name": "Server-Side Request Forgery (SSRF)",
            "description": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.",
            "capec_id": [
              664
            ],
            "scope": [
              "Access Control",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00689,
          "percentile": 0.51351,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-83548",
      "source_identifier": "user@sonicwall.com",
      "published": "2026-09-01T22:17:13Z",
      "last_modified": "2026-09-03T13:06:16Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": "2026-09-02",
      "cisa_action_due": "2026-09-05",
      "cisa_required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
      "cisa_vulnerability_name": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations."
        }
      ],
      "references": [
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016",
          "source": "user@sonicwall.com",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548",
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "tags": [
            "US Government Resource"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@sonicwall.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-441"
            },
            {
              "lang": "en",
              "value": "CWE-918"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "F160BF49-63F6-4458-AA1B-9D46AF320741",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.4.3-03526"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "51E4FB42-435D-41F7-AF37-8235E3478CB5",
                  "version_start_including": "12.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.5.0-02952"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "653B5F4D-7417-4A85-B385-46157A1540A6",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "796684A5-0639-4D62-8C3B-7E330F200964",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.4.3-03526"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "22DA8C27-F1AF-4136-AB59-4E03350B68AD",
                  "version_start_including": "12.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.5.0-02952"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "7B24D300-1154-49A1-A1F3-FB0CC717166A",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "70103B37-D895-4F07-B927-7CD4DE85DB9C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.4.3-03526"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "ACADD37E-AEE1-4B8A-9D49-5AB22D53C393",
                  "version_start_including": "12.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.5.0-02952"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "E9B414C5-C376-4216-A267-ABC0930905CE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma8200v",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.4.3-03526",
            "affected_versions_first": "12.4.3-02804",
            "affected_versions_last": "12.4.3-03453"
          },
          {
            "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma8200v",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "12.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.5.0-02952",
            "affected_versions_first": "12.5.0",
            "affected_versions_last": "12.5.0-02835"
          },
          {
            "criteria": "cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma8200v",
            "product_type": "a",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma6210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.4.3-03526",
            "affected_versions_first": "12.4.3-02804",
            "affected_versions_last": "12.4.3-03453"
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma6210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": "12.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.5.0-02952",
            "affected_versions_first": "12.5.0",
            "affected_versions_last": "12.5.0-02835"
          },
          {
            "criteria": "cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma6210",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma7210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.4.3-03526",
            "affected_versions_first": "12.4.3-02804",
            "affected_versions_last": "12.4.3-03453"
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma7210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": "12.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.5.0-02952",
            "affected_versions_first": "12.5.0",
            "affected_versions_last": "12.5.0-02835"
          },
          {
            "criteria": "cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma7210",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 441,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
            "description": "The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.",
            "capec_id": [
              219,
              465
            ],
            "scope": [
              "Access Control",
              "Non-Repudiation"
            ],
            "impact": [
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Hide Activities"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          },
          {
            "id": 918,
            "owasptop10_2021": "A10 Server-Side Request Forgery (SSRF)",
            "name": "Server-Side Request Forgery (SSRF)",
            "description": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.",
            "capec_id": [
              664
            ],
            "scope": [
              "Access Control",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.04667,
          "percentile": 0.91357,
          "date": "2026-09-21"
        },
        "cisa_kev": {
          "vendor_project": "SonicWall",
          "product": "SMA1000 Appliances",
          "vulnerability_name": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "date_added": "2026-09-02",
          "short_description": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
          "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
          "due_date": "2026-09-05",
          "known_ransomware_campaign_use": "Unknown",
          "notes": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548"
        },
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [CWE-89: SQL Injection](/reference/vulnerability/search/examples/enrichment-cwe-id/)
- [CWE Name: Deserialization of Untrusted Data](/reference/vulnerability/search/examples/enrichment-cwe-name/)
- [CWE Scope: Non-Repudiation](/reference/vulnerability/search/examples/enrichment-cwe-scope/)
- [CWE Impact: Hide Activities](/reference/vulnerability/search/examples/enrichment-cwe-impact/)
- [CWE Detectable by Fuzzing](/reference/vulnerability/search/examples/enrichment-cwe-detection-method/)
- [Affected CPE Names That Are Deprecated](/reference/vulnerability/search/examples/enrichment-cpe-cpe-names-deprecated/)
