Sonicwall

Sonicos

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.88%
  • Veröffentlicht 29.07.2025 21:11:59
  • Zuletzt bearbeitet 11.08.2025 14:59:40

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

Medienbericht
  • EPSS 0.82%
  • Veröffentlicht 23.04.2025 19:24:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

Medienbericht
  • EPSS 0.5%
  • Veröffentlicht 09.01.2025 09:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configu...

  • EPSS 0.8%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

  • EPSS 0.64%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

  • EPSS 0.71%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

  • EPSS 0.81%
  • Veröffentlicht 09.01.2025 08:15:26
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

Warnung Medienbericht
  • EPSS 95.13%
  • Veröffentlicht 09.01.2025 07:15:27
  • Zuletzt bearbeitet 04.08.2026 05:16:31

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

  • EPSS 0.74%
  • Veröffentlicht 09.01.2025 07:15:27
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

  • EPSS 0.34%
  • Veröffentlicht 09.01.2025 07:15:27
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.