Sonicwall

Sonicos

70 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 29.07.2025 21:11:59
  • Last modified 11.08.2025 14:59:40

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

Media report
  • EPSS 0.05%
  • Published 23.04.2025 19:24:53
  • Last modified 29.04.2025 13:52:47

A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

  • EPSS 0.07%
  • Published 09.01.2025 09:15:06
  • Last modified 09.01.2025 15:15:14

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configu...

  • EPSS 0.32%
  • Published 09.01.2025 08:15:26
  • Last modified 09.01.2025 15:15:15

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

  • EPSS 0.25%
  • Published 09.01.2025 08:15:26
  • Last modified 17.01.2025 03:15:07

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

  • EPSS 0.46%
  • Published 09.01.2025 08:15:26
  • Last modified 17.01.2025 03:15:07

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

  • EPSS 0.42%
  • Published 09.01.2025 08:15:26
  • Last modified 17.01.2025 03:15:06

A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

  • EPSS 0.06%
  • Published 09.01.2025 07:15:27
  • Last modified 09.01.2025 15:15:18

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

Warning Media report
  • EPSS 93.82%
  • Published 09.01.2025 07:15:27
  • Last modified 19.02.2025 15:33:49

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

  • EPSS 0.03%
  • Published 09.01.2025 07:15:27
  • Last modified 09.01.2025 16:16:21

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.