VYPR

Sonicos

by SonicWall

CVEs (78)

  • CVE-2026-0204HigApr 29, 2026
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

  • CVE-2023-0656HigMar 2, 2023
    risk 0.52cvss 7.5epss 0.41

    A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

  • CVE-2019-7487HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.00

    Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

  • CVE-2021-3450HigMar 25, 2021
    risk 0.50cvss 7.4epss 0.18

    The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve…

  • CVE-2019-12259HigAug 9, 2019
    risk 0.50cvss 7.5epss 0.16

    Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

  • CVE-2025-40601HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

  • CVE-2024-53705HigJan 9, 2025
    risk 0.49cvss 7.5epss 0.01

    A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

  • CVE-2024-40764HigJul 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

  • CVE-2024-29012HigJun 20, 2024
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

  • CVE-2023-41713HigOct 17, 2023
    risk 0.49cvss 7.5epss 0.01

    SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.

  • CVE-2022-22278HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

  • CVE-2022-22275HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.

  • CVE-2021-20019HigJun 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.

  • CVE-2021-20027HigJun 14, 2021
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls.

  • CVE-2020-5140HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads to memory addresses leak. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6…

  • CVE-2020-5139HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7,…

  • CVE-2020-5138HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12,…

  • CVE-2020-5137HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12,…

  • CVE-2020-5133HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall crash. This vulnerability affected SonicOS Gen 6 version 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

  • CVE-2019-7477HigApr 2, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are enabled. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2,…