VYPR

Sma 410 Firmware

by SonicWall

CVEs (35)

  • CVE-2024-45318HigDec 5, 2024
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

  • CVE-2025-40596HigJul 23, 2025
    risk 0.52cvss 7.3epss 0.56

    A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

  • CVE-2025-40597HigJul 23, 2025
    risk 0.51cvss 7.5epss 0.29

    A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

  • CVE-2021-20040HigDec 8, 2021
    risk 0.51cvss 7.5epss 0.25

    A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

  • CVE-2025-32821HigMay 7, 2025
    risk 0.49cvss 7.2epss 0.20

    A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

  • CVE-2024-40763HigDec 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.

  • CVE-2021-20050HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.

  • CVE-2021-20049HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.

  • CVE-2021-20041HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.07

    An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

  • CVE-2025-40598MedJul 23, 2025
    risk 0.44cvss 6.1epss 0.51

    A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

  • CVE-2024-45319MedDec 5, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.

  • CVE-2024-22395MedFeb 24, 2024
    risk 0.41cvss 6.3epss 0.00

    Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.

  • CVE-2024-53702MedDec 5, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

  • CVE-2022-22279MedApr 13, 2022
    risk 0.32cvss 4.9epss 0.01

    A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and…

  • CVE-2025-40603MedOct 31, 2025
    risk 0.29cvss 4.5epss 0.00

    A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

Page 2 of 2