Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-20050 An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, pot… Sma 100 Firmware 10.0.0.0+ Fix from $1,9502021-12-23 CRITICAL 9.8 CVE-2021-20042 An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi… Sma 200 Firmware Mitigation only Fix from $2,3002021-12-08 CRITICAL 9.8 CVE-2021-20045EPSS 25% A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execut… Sma 200 Firmware Mitigation only Fix from $2,3002021-12-08 HIGH 8.8 CVE-2021-20043EPSS 23% A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code… Sma 200 Firmware Mitigation only Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-20044EPSS 40% A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands… Sma 200 Firmware Mitigation only Fix from $1,9502021-12-08 HIGH 7.8 CVE-2021-20047 SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation v… Global Vpn Client after 4.10.6 Fix from $1,9502021-12-08 HIGH 7.5 CVE-2021-20041EPSS 7% An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfi… Sma 200 Firmware Mitigation only Fix from $1,9502021-12-08 CRITICAL 9.8 CVE-2021-20038 KEVEPSS 100% A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated atta… Sma 200 Firmware Mitigation only Fix from $2,3002021-12-08 HIGH 8.8 CVE-2021-20039EPSS 78% Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated att… Sma 200 Firmware No fix yet Fix from $1,9502021-12-08 HIGH 7.5 CVE-2021-20040EPSS 26% A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as… Sma 200 Firmware Mitigation only Fix from $1,9502021-12-08 MEDIUM 6.1 CVE-2021-20031EPSS 13% A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domain… Sonicos after 7.0.1-r1283 Fix from $1,6002021-10-12 CRITICAL 9.1 CVE-2021-20034EPSS 81% An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitra… Sma 200 Firmware after 10.2.1.0-17sv Fix from $2,3002021-09-27 MEDIUM 6.5 CVE-2021-20035 KEV Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as… Sma 200 Firmware 9.0.0.11-31sv / 10.2.0.8-37sv+ Fix from $1,6002021-09-27 HIGH 7.8 CVE-2021-20037 SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which … Global Vpn Client after 4.10.5 Fix from $1,9502021-09-21 CRITICAL 9.8 CVE-2021-20032 SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially … Analytics after 2.5.2518 Fix from $2,3002021-08-10 CRITICAL 9.8 CVE-2021-20028 KEVEPSS 30% Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifical… Sma 210 Firmware 9.0.0.10-28sv+ Fix from $2,3002021-08-04 HIGH 8.1 CVE-2021-20024 Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentia… Switch after 1.0.0.5-16 Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-20019 A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an int… Sonicos 7.0.0.376 / 7.0.1-r1036+ Fix from $1,9502021-06-23 HIGH 7.5 CVE-2021-20027 A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This v… Sonicos after 7.0.1-r1262 Fix from $1,9502021-06-14 HIGH 8.8 CVE-2021-20026EPSS 12% A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. T… Network Security Manager 2.2.0+ Fix from $1,9502021-05-27 HIGH 7.8 CVE-2021-20025 SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setu… Email Security Virtual Appliance after 10.0.9 Fix from $1,9502021-05-13 CRITICAL 9.8 CVE-2021-20020 A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root. Global Management System Mitigation only Fix from $2,3002021-04-10 CRITICAL 9.8 CVE-2021-20021 KEVEPSS 83% A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP req… Email Security 10.0.9.6103 / 10.0.9.6105+ Fix from $2,3002021-04-09 HIGH 7.2 CVE-2021-20022 KEVEPSS 17% SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remot… Email Security 10.0.9.6103 / 10.0.9.6105+ Fix from $1,9502021-04-09 HIGH 8.8 CVE-2021-20017 A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. … Sma100 Firmware after 10.2.0.5 Fix from $1,9502021-03-13 HIGH 8.2 CVE-2020-5148 SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential atta… Directory Services Connector 4.1.19+ Fix from $1,9502021-03-05 CRITICAL 9.8 CVE-2021-20016 KEVEPSS 37% A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username… Sma 100 Firmware 10.2.0.5-d-29sv+ Fix from $2,3002021-02-04 MEDIUM 5.3 CVE-2020-5147 SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in t… Netextender after 10.2.300 Fix from $1,6002021-01-09 HIGH 7.2 CVE-2020-5146 A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This… Sma 100 Firmware after 10.2.0.2-20sv Fix from $1,9502021-01-09 HIGH 8.6 CVE-2020-5145 SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation c… Global Vpn Client after 4.10.4.0314 Fix from $1,9502020-10-28