Sonicos
by SonicWall
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-9867 | Med | 0.36 | 5.5 | 0.00 | Feb 19, 2019 | In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version… | ||
| CVE-2024-22396 | Med | 0.35 | 5.3 | 0.01 | Mar 14, 2024 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. | ||
| CVE-2022-22277 | Med | 0.35 | 5.3 | 0.01 | Apr 27, 2022 | A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext. | ||
| CVE-2022-22276 | Med | 0.35 | 5.3 | 0.01 | Apr 27, 2022 | A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user. | ||
| CVE-2020-5143 | Med | 0.35 | 5.3 | 0.02 | Oct 12, 2020 | SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3,… | ||
| CVE-2020-5132 | Med | 0.35 | 5.3 | 0.01 | Sep 30, 2020 | SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an… | ||
| CVE-2020-5130 | Med | 0.35 | 5.3 | 0.01 | Jul 17, 2020 | SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier. | ||
| CVE-2018-5281 | Med | 0.35 | 5.4 | 0.03 | Jan 8, 2018 | SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens. | ||
| CVE-2018-5280 | Med | 0.35 | 5.4 | 0.03 | Jan 8, 2018 | SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens. | ||
| CVE-2026-0206 | Med | 0.32 | 4.9 | 0.01 | Apr 29, 2026 | A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. | ||
| CVE-2026-3439 | Med | 0.32 | 4.9 | 0.00 | Mar 4, 2026 | A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. | ||
| CVE-2026-0402 | Med | 0.32 | 4.9 | 0.00 | Feb 24, 2026 | A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. | ||
| CVE-2026-0401 | Med | 0.32 | 4.9 | 0.00 | Feb 24, 2026 | A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. | ||
| CVE-2026-0400 | Med | 0.32 | 4.9 | 0.00 | Feb 24, 2026 | A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. | ||
| CVE-2026-0399 | Med | 0.32 | 4.9 | 0.00 | Feb 24, 2026 | Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. | ||
| CVE-2024-12806 | Med | 0.32 | 4.9 | 0.01 | Jan 9, 2025 | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file. | ||
| CVE-2026-0516 | Med | 0.00 | 6.5 | 0.00 | Aug 5, 2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. | ||
| CVE-2015-3447 | 0.00 | — | 0.02 | Apr 29, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter. |
- risk 0.36cvss 5.5epss 0.00
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version…
- risk 0.35cvss 5.3epss 0.01
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
- risk 0.35cvss 5.3epss 0.02
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3,…
- risk 0.35cvss 5.3epss 0.01
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an…
- risk 0.35cvss 5.3epss 0.01
SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.
- risk 0.35cvss 5.4epss 0.03
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
- risk 0.35cvss 5.4epss 0.03
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
- risk 0.32cvss 4.9epss 0.01
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
- risk 0.32cvss 4.9epss 0.00
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.
- risk 0.32cvss 4.9epss 0.00
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
- risk 0.32cvss 4.9epss 0.00
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
- risk 0.32cvss 4.9epss 0.00
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
- risk 0.32cvss 4.9epss 0.00
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.
- risk 0.32cvss 4.9epss 0.01
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
- risk 0.00cvss 6.5epss 0.00
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
- CVE-2015-3447Apr 29, 2015risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.
Page 4 of 4