VYPR

Sonicos

by SonicWall

CVEs (78)

  • CVE-2018-9867MedFeb 19, 2019
    risk 0.36cvss 5.5epss 0.00

    In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version…

  • CVE-2024-22396MedMar 14, 2024
    risk 0.35cvss 5.3epss 0.01

    An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

  • CVE-2022-22277MedApr 27, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.

  • CVE-2022-22276MedApr 27, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.

  • CVE-2020-5143MedOct 12, 2020
    risk 0.35cvss 5.3epss 0.02

    SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3,…

  • CVE-2020-5132MedSep 30, 2020
    risk 0.35cvss 5.3epss 0.01

    SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an…

  • CVE-2020-5130MedJul 17, 2020
    risk 0.35cvss 5.3epss 0.01

    SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.

  • CVE-2018-5281MedJan 8, 2018
    risk 0.35cvss 5.4epss 0.03

    SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

  • CVE-2018-5280MedJan 8, 2018
    risk 0.35cvss 5.4epss 0.03

    SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

  • CVE-2026-0206MedApr 29, 2026
    risk 0.32cvss 4.9epss 0.01

    A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-3439MedMar 4, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

  • CVE-2026-0402MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-0401MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-0400MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-0399MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.

  • CVE-2024-12806MedJan 9, 2025
    risk 0.32cvss 4.9epss 0.01

    A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

  • CVE-2026-0516MedAug 5, 2026
    risk 0.00cvss 6.5epss 0.00

    A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

  • CVE-2015-3447Apr 29, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.

Page 4 of 4