Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sonicosv CRITICAL 9.8
CVE-2019-7475

A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced…

Fix: after 5.9.1.10
Fix from $2,300 2019-04-02
Sonicosv HIGH 7.5
CVE-2019-7477

A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are…

Fix: after 5.9.1.10
Fix from $1,950 2019-04-02
Sonicosv MEDIUM 6.5
CVE-2019-7474

A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading cert…

Fix: after 5.9.1.10
Fix from $1,600 2019-04-02
Sonicosv MEDIUM 5.5
CVE-2018-9867

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the Sonic…

Fix: after 5.9.1.10
Fix from $1,600 2019-02-19
Global Management System CRITICAL 9.8
CVE-2018-9866

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance…

Fix: after 8.1
Fix from $2,300 2018-08-03
Analyzer MEDIUM 5.4
CVE-2018-5691

SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.

Fix: after 8.4
Fix from $1,600 2018-01-14
Sonicos MEDIUM 5.4
CVE-2018-5280

SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

No fix yet
Fix from $1,600 2018-01-08
Sonicos MEDIUM 5.4
CVE-2018-5281

SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

No fix yet
Fix from $1,600 2018-01-08
Uma Em5000 Firmware CRITICAL 9.8
CVE-2016-2397EPSS 6%

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deseri…

Mitigation only
Fix from $2,300 2016-02-17
Analyzer CRITICAL 9.9
CVE-2016-2396

The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…

Mitigation only
Fix from $2,300 2016-02-17
Netextender MEDIUM 6.9
CVE-2015-4173

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the…

Fix: 7.5.227 / 8.0.238+
Fix from $1,600 2015-08-26
Uma Em5000 Firmware HIGH 9.0
CVE-2015-3990

The GMS ViewPoint (GMSVP) web application in Dell Sonicwall GMS, Analyzer, and UMA EM5000 before 7.2 SP4 allows remote authenticated users to execute…

Fix: after 7.2
Fix from $1,950 2015-05-20
Remote Access Firmware MEDIUM 6.8
CVE-2015-2248

Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0…

Fix: 7.5.1.0-38sv / 8.0.0.1-16sv+
Fix from $1,600 2015-05-01
Analyzer HIGH 9.0
CVE-2014-8420EPSS 24%

The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b…

Mitigation only
Fix from $1,950 2014-11-25
Scrutinizer MEDIUM 6.5
CVE-2014-4977EPSS 75%

Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via th…

No fix yet
Fix from $1,600 2014-07-16
Scrutinizer MEDIUM 5.5
CVE-2014-4976

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…

No fix yet
Fix from $1,600 2014-07-16
Aventail Sra Ex Virtual Appliance HIGH 7.5
CVE-2011-5262

SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parame…

No fix yet
Fix from $1,950 2013-02-12
Scrutinizer HIGH 7.5
CVE-2012-3951EPSS 52%

The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scruti…

Fix: after 9.0.1.19899
Fix from $1,950 2012-07-31
Scrutinizer HIGH 9.4
CVE-2012-2627EPSS 6%

d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…

Fix: 9.5.0+
Fix from $1,950 2012-07-31
Scrutinizer MEDIUM 5.0
CVE-2012-2626EPSS 44%

cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…

Fix: 9.5.0+
Fix from $1,600 2012-07-31
Scrutinizer MEDIUM 6.5
CVE-2012-2962EPSS 67%

SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated u…

Fix: 9.5.2+
Fix from $1,600 2012-07-30
Ssl Vpn End Point Interrogator\/installer Activex Control HIGH 9.3
CVE-2010-2583

Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hot…

Fix: after 10.5.1
Fix from $1,950 2010-11-03
Global Vpn Client HIGH 9.3
CVE-2007-6273EPSS 6%

Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote atta…

No fix yet
Fix from $1,950 2007-12-07
Ssl Vpn 200 HIGH 10.0
CVE-2007-5815

Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 befor…

Fix: after 2.5
Fix from $1,950 2007-11-05
Ssl Vpn HIGH 9.3
CVE-2007-5603EPSS 38%

Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remo…

Fix: after 2.5
Fix from $1,950 2007-11-05
Ssl Vpn HIGH 9.3
CVE-2007-5814EPSS 6%

Multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote …

Fix: after 2.5
Fix from $1,950 2007-11-05
Pro100 HIGH 7.8
CVE-2003-1490

SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal inter…

Mitigation only
Fix from $1,950 2003-12-31
Firmware MEDIUM 5.1
CVE-2003-1320

SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key E…

Fix: after 6.4.0.1
Fix from $1,600 2003-12-31
Content Filtering MEDIUM 5.0
CVE-2002-2181

SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.

Mitigation only
Fix from $1,600 2002-12-31
Soho Firmware HIGH 7.5
CVE-2001-1104EPSS 7%

SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.

Mitigation only
Fix from $1,950 2001-07-25