Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sma 100 Firmware HIGH 7.5
CVE-2021-20050

An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, pot…

Fix: 10.0.0.0+
Fix from $1,950 2021-12-23
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20042

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…

Mitigation only
Fix from $2,300 2021-12-08
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20045EPSS 25%

A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execut…

Mitigation only
Fix from $2,300 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20043EPSS 23%

A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20044EPSS 40%

A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands…

Mitigation only
Fix from $1,950 2021-12-08
Global Vpn Client HIGH 7.8
CVE-2021-20047

SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation v…

Fix: after 4.10.6
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 7.5
CVE-2021-20041EPSS 7%

An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfi…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20038 KEVEPSS 100%

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated atta…

Mitigation only
Fix from $2,300 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20039EPSS 78%

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated att…

No fix yet
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 7.5
CVE-2021-20040EPSS 26%

A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as…

Mitigation only
Fix from $1,950 2021-12-08
Sonicos MEDIUM 6.1
CVE-2021-20031EPSS 13%

A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domain…

Fix: after 7.0.1-r1283
Fix from $1,600 2021-10-12
Sma 200 Firmware CRITICAL 9.1
CVE-2021-20034EPSS 81%

An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitra…

Fix: after 10.2.1.0-17sv
Fix from $2,300 2021-09-27
Sma 200 Firmware MEDIUM 6.5
CVE-2021-20035 KEV

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as…

Fix: 9.0.0.11-31sv / 10.2.0.8-37sv+
Fix from $1,600 2021-09-27
Global Vpn Client HIGH 7.8
CVE-2021-20037

SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which …

Fix: after 4.10.5
Fix from $1,950 2021-09-21
Analytics CRITICAL 9.8
CVE-2021-20032

SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially …

Fix: after 2.5.2518
Fix from $2,300 2021-08-10
Sma 210 Firmware CRITICAL 9.8
CVE-2021-20028 KEVEPSS 30%

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifical…

Fix: 9.0.0.10-28sv+
Fix from $2,300 2021-08-04
Switch HIGH 8.1
CVE-2021-20024

Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentia…

Fix: after 1.0.0.5-16
Fix from $1,950 2021-07-09
Sonicos HIGH 7.5
CVE-2021-20019

A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an int…

Fix: 7.0.0.376 / 7.0.1-r1036+
Fix from $1,950 2021-06-23
Sonicos HIGH 7.5
CVE-2021-20027

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This v…

Fix: after 7.0.1-r1262
Fix from $1,950 2021-06-14
Network Security Manager HIGH 8.8
CVE-2021-20026EPSS 12%

A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. T…

Fix: 2.2.0+
Fix from $1,950 2021-05-27
Email Security Virtual Appliance HIGH 7.8
CVE-2021-20025

SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setu…

Fix: after 10.0.9
Fix from $1,950 2021-05-13
Global Management System CRITICAL 9.8
CVE-2021-20020

A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.

Mitigation only
Fix from $2,300 2021-04-10
Email Security CRITICAL 9.8
CVE-2021-20021 KEVEPSS 83%

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP req…

Fix: 10.0.9.6103 / 10.0.9.6105+
Fix from $2,300 2021-04-09
Email Security HIGH 7.2
CVE-2021-20022 KEVEPSS 17%

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remot…

Fix: 10.0.9.6103 / 10.0.9.6105+
Fix from $1,950 2021-04-09
Sma100 Firmware HIGH 8.8
CVE-2021-20017

A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. …

Fix: after 10.2.0.5
Fix from $1,950 2021-03-13
Directory Services Connector HIGH 8.2
CVE-2020-5148

SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential atta…

Fix: 4.1.19+
Fix from $1,950 2021-03-05
Sma 100 Firmware CRITICAL 9.8
CVE-2021-20016 KEVEPSS 37%

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username…

Fix: 10.2.0.5-d-29sv+
Fix from $2,300 2021-02-04
Netextender MEDIUM 5.3
CVE-2020-5147

SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in t…

Fix: after 10.2.300
Fix from $1,600 2021-01-09
Sma 100 Firmware HIGH 7.2
CVE-2020-5146

A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This…

Fix: after 10.2.0.2-20sv
Fix from $1,950 2021-01-09
Global Vpn Client HIGH 8.6
CVE-2020-5145

SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation c…

Fix: after 4.10.4.0314
Fix from $1,950 2020-10-28