Sonicwall

Sonicos

76 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 17.01.2025 03:15:07

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

  • EPSS 1.08%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 17.01.2025 03:15:07

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

  • EPSS 1.95%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 17.01.2025 03:15:06

A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

  • EPSS 0.73%
  • Veröffentlicht 09.01.2025 07:15:27
  • Zuletzt bearbeitet 09.01.2025 16:16:21

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.

  • EPSS 0.22%
  • Veröffentlicht 09.01.2025 07:15:27
  • Zuletzt bearbeitet 09.01.2025 15:15:18

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

Warnung Medienbericht
  • EPSS 94.01%
  • Veröffentlicht 09.01.2025 07:15:27
  • Zuletzt bearbeitet 31.10.2025 15:56:33

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

  • EPSS 0.03%
  • Veröffentlicht 09.01.2025 07:15:26
  • Zuletzt bearbeitet 09.01.2025 15:15:15

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

Warnung Medienbericht
  • EPSS 4.69%
  • Veröffentlicht 23.08.2024 07:15:03
  • Zuletzt bearbeitet 31.10.2025 15:56:26

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firew...

  • EPSS 6.41%
  • Veröffentlicht 18.07.2024 08:15:02
  • Zuletzt bearbeitet 21.11.2024 09:31:34

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

Medienbericht
  • EPSS 23.85%
  • Veröffentlicht 09.07.2024 12:15:20
  • Zuletzt bearbeitet 04.11.2025 18:16:31

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Respon...