VYPR

Vendor CVEs

SonicWall

All CVEs

273 total · sorted by risk
  • CVE-2020-5147MedJan 9, 2021
    risk 0.38cvss 5.3epss 0.02

    SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.

  • CVE-2026-66151MedAug 7, 2026
    risk 0.36cvss 5.5epss 0.00

    SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

  • CVE-2025-23007MedJan 30, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.

  • CVE-2024-45315MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of…

  • CVE-2023-6340MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.

  • CVE-2018-9867MedFeb 19, 2019
    risk 0.36cvss 5.5epss 0.00

    In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version…

  • CVE-2024-22396MedMar 14, 2024
    risk 0.35cvss 5.3epss 0.01

    An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

  • CVE-2023-34131MedJul 13, 2023
    risk 0.35cvss 5.3epss 0.01

    Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access restricted web pages. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-0655MedFeb 14, 2023
    risk 0.35cvss 5.3epss 0.01

    SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses.

  • CVE-2022-22277MedApr 27, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.

  • CVE-2022-22276MedApr 27, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.

  • CVE-2020-5143MedOct 12, 2020
    risk 0.35cvss 5.3epss 0.02

    SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3,…

  • CVE-2020-5132MedSep 30, 2020
    risk 0.35cvss 5.3epss 0.01

    SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an…

  • CVE-2020-5130MedJul 17, 2020
    risk 0.35cvss 5.3epss 0.01

    SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.

  • CVE-2018-5691MedJan 14, 2018
    risk 0.35cvss 5.4epss 0.01

    SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.

  • CVE-2018-5281MedJan 8, 2018
    risk 0.35cvss 5.4epss 0.03

    SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

  • CVE-2018-5280MedJan 8, 2018
    risk 0.35cvss 5.4epss 0.03

    SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

  • CVE-2025-40605MedNov 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

  • CVE-2024-53702MedDec 5, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

  • CVE-2026-0206MedApr 29, 2026
    risk 0.32cvss 4.9epss 0.01

    A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-3439MedMar 4, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

  • CVE-2026-0402MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-0401MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-0400MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

  • CVE-2026-0399MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.00

    Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.

  • CVE-2024-12806MedJan 9, 2025
    risk 0.32cvss 4.9epss 0.01

    A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

  • CVE-2024-22398MedMar 14, 2024
    risk 0.32cvss 4.9epss 0.01

    An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance…

  • CVE-2022-22279MedApr 13, 2022
    risk 0.32cvss 4.9epss 0.01

    A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and…

  • CVE-2021-20018MedMar 13, 2021
    risk 0.32cvss 4.9epss 0.01

    A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.

  • CVE-2026-3468MedMar 31, 2026
    risk 0.31cvss 4.8epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute…

  • CVE-2025-40603MedOct 31, 2025
    risk 0.29cvss 4.5epss 0.00

    A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

  • CVE-2026-3470LowMar 31, 2026
    risk 0.25cvss 3.8epss 0.00

    A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.

  • CVE-2026-15410HigKEVJul 14, 2026
    risk 0.24cvss 7.2epss 0.12

    Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute…

  • CVE-2026-15409CriKEVJul 14, 2026
    risk 0.24cvss 10.0epss 0.85

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

  • CVE-2026-3469LowMar 31, 2026
    risk 0.18cvss 2.7epss 0.00

    A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

  • CVE-2014-4977Jul 16, 2014
    risk 0.09cvss —epss 0.75

    Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit…

  • CVE-2012-2962Jul 30, 2012
    risk 0.08cvss —epss 0.67

    SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.

  • CVE-2012-3951Jul 31, 2012
    risk 0.07cvss —epss 0.52

    The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.

  • CVE-2012-2626Jul 31, 2012
    risk 0.07cvss —epss 0.44

    cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.

  • CVE-2007-5603Nov 5, 2007
    risk 0.06cvss —epss 0.38

    Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.

  • CVE-2014-8420Nov 25, 2014
    risk 0.05cvss —epss 0.24

    The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors.

  • CVE-2008-4918Nov 4, 2008
    risk 0.04cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content…

  • CVE-2005-1006May 2, 2005
    risk 0.04cvss —epss 0.06

    Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.

  • CVE-2001-1104Jul 25, 2001
    risk 0.04cvss —epss 0.07

    SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.

  • CVE-2015-2248May 1, 2015
    risk 0.03cvss —epss 0.04

    Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks…

  • CVE-2014-2879Apr 17, 2014
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2)…

  • CVE-2013-7025Dec 9, 2013
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script…

  • CVE-2011-5262Feb 12, 2013
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

  • CVE-2011-5169Sep 15, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.

  • CVE-2012-3848Jul 31, 2012
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to d4d/exporters.php, (2) the HTTP Referer header to…

Page 5 of 6