Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Global Vpn Client HIGH 7.8
CVE-2020-5144

SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process h…

Fix: after 4.10.4.0314
Fix from $1,950 2020-10-28
Sonicos HIGH 7.5
CVE-2020-5140

A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a mali…

Fix: after 6.5.4.7
Fix from $1,950 2020-10-12
Sonicos MEDIUM 6.5
CVE-2020-5141

A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vuln…

Fix: after 6.5.4.7
Fix from $1,600 2020-10-12
Sonicos MEDIUM 6.1
CVE-2020-5142

A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and …

Fix: after 6.5.4.7
Fix from $1,600 2020-10-12
Sonicos MEDIUM 5.3
CVE-2020-5143

SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the ser…

Fix: after 6.5.4.7
Fix from $1,600 2020-10-12
Sonicos CRITICAL 9.8
CVE-2020-5135 KEVEPSS 25%

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sendin…

Fix: after 6.5.4.7
Fix from $2,300 2020-10-12
Sonicos HIGH 7.5
CVE-2020-5133

A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall cras…

Fix: after 6.5.4.4
Fix from $1,950 2020-10-12
Sonicos HIGH 7.5
CVE-2020-5137

A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service a…

Fix: after 6.5.4.7
Fix from $1,950 2020-10-12
Sonicos HIGH 7.5
CVE-2020-5138

A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service…

Fix: after 6.5.4.7
Fix from $1,950 2020-10-12
Sonicos HIGH 7.5
CVE-2020-5139

A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid poi…

Fix: after 6.5.4.7
Fix from $1,950 2020-10-12
Sonicos MEDIUM 6.5
CVE-2020-5134

A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a firewall crash. This vulnerabilit…

Fix: after 6.5.4.4
Fix from $1,600 2020-10-12
Sonicos MEDIUM 6.5
CVE-2020-5136

A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assist portal…

Fix: after 6.5.4.7
Fix from $1,600 2020-10-12
Sma100 Firmware MEDIUM 5.3
CVE-2020-5132

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerab…

Mitigation only
Fix from $1,600 2020-09-30
Netextender HIGH 7.8
CVE-2020-5131

SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with …

Fix: after 9.0.815
Fix from $1,950 2020-07-17
Sonicos MEDIUM 5.3
CVE-2020-5130

SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This…

Fix: after 6.5.4.4-44n
Fix from $1,600 2020-07-17
Sma1000 Firmware HIGH 7.5
CVE-2020-5129

A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Den…

Fix: after 12.1.0-06411
Fix from $1,950 2020-03-26
Analyzer CRITICAL 9.8
CVE-2013-1359EPSS 89%

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal M…

No fix yet
Fix from $2,300 2020-02-11
Analyzer CRITICAL 9.8
CVE-2013-1360EPSS 23%

An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal M…

No fix yet
Fix from $2,300 2020-02-11
Sonicos HIGH 7.2
CVE-2019-7479

A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen…

Fix: after 5.9.1.12-4o
Fix from $1,950 2019-12-31
Global Management System CRITICAL 9.8
CVE-2019-7478

A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, …

Mitigation only
Fix from $2,300 2019-12-31
Email Security Appliance CRITICAL 9.8
CVE-2019-7488

Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulne…

Fix: after 10.0.2
Fix from $2,300 2019-12-23
Email Security Appliance CRITICAL 9.8
CVE-2019-7489EPSS 5%

A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Ema…

Fix: after 10.0.2
Fix from $2,300 2019-12-23
Sma 100 Firmware HIGH 8.8
CVE-2019-7486

Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA10…

Fix: after 9.0.0.4
Fix from $1,950 2019-12-19
Sonicos HIGH 7.8
CVE-2019-7487

Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a…

Fix: after 6.5.3.3
Fix from $1,950 2019-12-19
Sma 100 Firmware CRITICAL 9.8
CVE-2019-7482EPSS 9%

Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability im…

Fix: after 9.0.0.3
Fix from $2,300 2019-12-19
Sma 100 Firmware HIGH 8.8
CVE-2019-7485

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA…

Fix: after 9.0.0.3
Fix from $1,950 2019-12-19
Sma 100 Firmware HIGH 7.5
CVE-2019-7483 KEV

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a …

Fix: 9.0.0.4+
Fix from $1,950 2019-12-19
Sma 100 Firmware MEDIUM 6.5
CVE-2019-7484

Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulne…

Fix: after 9.0.0.3
Fix from $1,600 2019-12-19
Sma 100 Firmware HIGH 7.5
CVE-2019-7481 KEVEPSS 100%

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 ve…

Fix: 9.0.0.4+
Fix from $1,950 2019-12-17
Global Management System HIGH 8.1
CVE-2019-7476

A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnera…

Fix: after 8.3
Fix from $1,950 2019-04-26