Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Analytics CRITICAL 9.8
CVE-2023-34124EPSS 46%

The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects …

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34128

Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics HIGH 8.8
CVE-2023-34126

Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This…

Fix: 9.3.2+
Fix from $1,950 2023-07-13
Analytics HIGH 8.8
CVE-2023-34127EPSS 86%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enable…

Fix: 9.3.2+
Fix from $1,950 2023-07-13
Analytics MEDIUM 6.5
CVE-2023-34125EPSS 25%

Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root p…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Global Management System HIGH 7.5
CVE-2023-34123

Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Anal…

Fix: 2.5.0.4 / 9.3.2+
Fix from $1,950 2023-07-13
Sonicos HIGH 8.8
CVE-2023-1101

SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.

Fix: 7.0.1-5111+
Fix from $1,950 2023-03-02
Sonicos HIGH 7.5
CVE-2023-0656EPSS 41%

A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cau…

Fix: after 7.0.1-5111
Fix from $1,950 2023-03-02
Email Security MEDIUM 5.3
CVE-2023-0655

SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive…

Fix: after 10.0.19.7431
Fix from $1,600 2023-02-14
Sma1000 Firmware HIGH 7.5
CVE-2023-0126EPSS 73%

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary file…

Mitigation only
Fix from $1,950 2023-01-19
Global Management System HIGH 7.5
CVE-2021-20030

SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing applicat…

Fix: 9.3.2+
Fix from $1,950 2022-10-13
Sma 200 Firmware HIGH 8.8
CVE-2022-2915

A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) …

Fix: after 10.2.1.5-34sv
Fix from $1,950 2022-08-26
Analytics CRITICAL 9.8
CVE-2022-22280EPSS 10%

Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…

Fix: 9.3.1+
Fix from $2,300 2022-07-29
Hosted Email Security HIGH 7.5
CVE-2022-2324

Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the app…

Fix: after 10.0.17.7319
Fix from $1,950 2022-07-29
Sws12 10fpoe Firmware HIGH 8.8
CVE-2022-2323EPSS 6%

Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host …

Fix: 1.2.0.0-3+
Fix from $1,950 2022-07-29
Sma 210 Firmware HIGH 8.8
CVE-2022-1703EPSS 12%

Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inj…

Fix: after 10.2.1.4-31sv
Fix from $1,950 2022-06-08
Sma 6200 Firmware CRITICAL 9.8
CVE-2022-22282EPSS 8%

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an…

Mitigation only
Fix from $2,300 2022-05-13
Netextender HIGH 7.8
CVE-2022-22281

A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attac…

Fix: after 10.2.322
Fix from $1,950 2022-05-13
Sma 6200 Firmware HIGH 7.5
CVE-2022-1701

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

Mitigation only
Fix from $1,950 2022-05-13
Sma 6200 Firmware MEDIUM 6.1
CVE-2022-1702EPSS 9%

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site …

Mitigation only
Fix from $1,600 2022-05-13
Global Vpn Client HIGH 7.8
CVE-2021-20051

SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of …

Fix: after 4.10.7.1117
Fix from $1,950 2022-05-04
Sonicos HIGH 7.5
CVE-2022-22275

Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially…

Fix: after 7.0.1-5030-r2007
Fix from $1,950 2022-04-27
Tz300p Firmware HIGH 7.5
CVE-2022-22278

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try t…

Fix: 7.0.1 / 7.0.1.0+
Fix from $1,950 2022-04-27
Tz300p Firmware MEDIUM 5.3
CVE-2022-22276

A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.

Fix: 7.0.1 / 7.0.1.0+
Fix from $1,600 2022-04-27
Tz300p Firmware MEDIUM 5.3
CVE-2022-22277

A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.

Fix: 6.5.4.10 / 7.0.1.0+
Fix from $1,600 2022-04-27
Sonicos CRITICAL 9.8
CVE-2022-22274EPSS 58%

A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS)…

Fix: after 7.0.1-5050
Fix from $2,300 2022-03-25
Sma 200 Firmware CRITICAL 9.8
CVE-2022-22273

Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…

Fix: after 9.0.0.9-26sv
Fix from $2,300 2022-03-17
Sonicos HIGH 8.8
CVE-2021-20046

A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (D…

Fix: after 7.0.1-5023-1349
Fix from $1,950 2022-01-10
Sonicos HIGH 8.8
CVE-2021-20048

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) a…

Fix: after 7.0.1-5023-1349
Fix from $1,950 2022-01-10
Sma 100 Firmware HIGH 7.5
CVE-2021-20049

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the …

Fix: 10.0.0.0+
Fix from $1,950 2021-12-23