Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sonicos HIGH 7.5
CVE-2024-40764

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

Fix: 6.5.4.v-21s-rc2457 / 7.0.1-5161+
Fix from $1,950 2024-07-18
Sonicos HIGH 7.5
CVE-2024-29012

Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via ssc…

Fix: 7.0.1-5161 / 7.1.1-7058+
Fix from $1,950 2024-06-20
Sonicos MEDIUM 6.5
CVE-2024-29013

Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy f…

Fix: 7.0.1-5161 / 7.1.1-7058+
Fix from $1,600 2024-06-20
Sma 200 Firmware MEDIUM 6.3
CVE-2024-22395

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially…

Fix: 10.2.1.11-65sv+
Fix from $1,600 2024-02-24
Sonicos CRITICAL 9.8
CVE-2024-22394

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …

Mitigation only
Fix from $2,300 2024-02-08
Capture Client MEDIUM 5.5
CVE-2023-6340

SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driv…

Fix: after 10.2.337
Fix from $1,600 2024-01-18
Sma 200 Firmware HIGH 8.8
CVE-2023-5970

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain use…

Fix: after 10.2.1.9-57sv
Fix from $1,950 2023-12-05
Sma 200 Firmware HIGH 7.2
CVE-2023-44221 KEVEPSS 75%

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative pri…

Fix: after 10.2.1.9-57sv
Fix from $1,950 2023-12-05
Directory Services Connector HIGH 7.8
CVE-2023-44219

A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local lo…

Fix: 4.1.22+
Fix from $1,950 2023-10-27
Netextender HIGH 7.3
CVE-2023-44220

SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-u…

Fix: after 10.2.336
Fix from $1,950 2023-10-27
Sonicos HIGH 8.8
CVE-2023-41715

SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside…

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,950 2023-10-17
Sonicos HIGH 7.5
CVE-2023-41713

SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,950 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-41711

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-41712

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-39276

SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-39277

SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall …

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-39278

SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-39279

SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Sonicos MEDIUM 6.5
CVE-2023-39280

SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,600 2023-10-17
Netextender HIGH 7.8
CVE-2023-44217

A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileg…

Fix: after 10.2.336
Fix from $1,950 2023-10-03
Netextender HIGH 7.8
CVE-2023-44218

A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYST…

Fix: after 10.2.336
Fix from $1,950 2023-10-03
Analytics CRITICAL 9.8
CVE-2023-34132EPSS 8%

Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff…

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34136

Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34137

SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics HIGH 7.5
CVE-2023-34133EPSS 73%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthent…

Fix: 9.3.2+
Fix from $1,950 2023-07-13
Analytics MEDIUM 6.5
CVE-2023-34134

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read adminis…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Analytics MEDIUM 6.5
CVE-2023-34135

Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file s…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Analytics MEDIUM 5.3
CVE-2023-34131

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34130

SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.…

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics HIGH 8.8
CVE-2023-34129EPSS 41%

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated r…

Fix: 9.3.2+
Fix from $1,950 2023-07-13