Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-40764 Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). Sonicos 6.5.4.v-21s-rc2457 / 7.0.1-5161+ Fix from $1,9502024-07-18 HIGH 7.5 CVE-2024-29012 Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via ssc… Sonicos 7.0.1-5161 / 7.1.1-7058+ Fix from $1,9502024-06-20 MEDIUM 6.5 CVE-2024-29013 Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy f… Sonicos 7.0.1-5161 / 7.1.1-7058+ Fix from $1,6002024-06-20 MEDIUM 6.3 CVE-2024-22395 Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially… Sma 200 Firmware 10.2.1.11-65sv+ Fix from $1,6002024-02-24 CRITICAL 9.8 CVE-2024-22394 An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote … Sonicos Mitigation only Fix from $2,3002024-02-08 MEDIUM 5.5 CVE-2023-6340 SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driv… Capture Client after 10.2.337 Fix from $1,6002024-01-18 HIGH 8.8 CVE-2023-5970 Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain use… Sma 200 Firmware after 10.2.1.9-57sv Fix from $1,9502023-12-05 HIGH 7.2 CVE-2023-44221 KEVEPSS 75% Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative pri… Sma 200 Firmware after 10.2.1.9-57sv Fix from $1,9502023-12-05 HIGH 7.8 CVE-2023-44219 A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local lo… Directory Services Connector 4.1.22+ Fix from $1,9502023-10-27 HIGH 7.3 CVE-2023-44220 SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-u… Netextender after 10.2.336 Fix from $1,9502023-10-27 HIGH 8.8 CVE-2023-41715 SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside… Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-41713 SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,9502023-10-17 MEDIUM 6.5 CVE-2023-41711 SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 MEDIUM 6.5 CVE-2023-41712 SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 MEDIUM 6.5 CVE-2023-39276 SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 MEDIUM 6.5 CVE-2023-39277 SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall … Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 MEDIUM 6.5 CVE-2023-39278 SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 MEDIUM 6.5 CVE-2023-39279 SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 MEDIUM 6.5 CVE-2023-39280 SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,6002023-10-17 HIGH 7.8 CVE-2023-44217 A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileg… Netextender after 10.2.336 Fix from $1,9502023-10-03 HIGH 7.8 CVE-2023-44218 A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYST… Netextender after 10.2.336 Fix from $1,9502023-10-03 CRITICAL 9.8 CVE-2023-34132EPSS 8% Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff… Analytics 9.3.2+ Fix from $2,3002023-07-13 CRITICAL 9.8 CVE-2023-34136 Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.… Analytics 9.3.2+ Fix from $2,3002023-07-13 CRITICAL 9.8 CVE-2023-34137 SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass … Analytics 9.3.2+ Fix from $2,3002023-07-13 HIGH 7.5 CVE-2023-34133EPSS 73% Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthent… Analytics 9.3.2+ Fix from $1,9502023-07-13 MEDIUM 6.5 CVE-2023-34134 Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read adminis… Analytics 9.3.2+ Fix from $1,6002023-07-13 MEDIUM 6.5 CVE-2023-34135 Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file s… Analytics 9.3.2+ Fix from $1,6002023-07-13 MEDIUM 5.3 CVE-2023-34131 Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access… Analytics 9.3.2+ Fix from $1,6002023-07-13 CRITICAL 9.8 CVE-2023-34130 SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.… Analytics 9.3.2+ Fix from $2,3002023-07-13 HIGH 8.8 CVE-2023-34129EPSS 41% Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated r… Analytics 9.3.2+ Fix from $1,9502023-07-13