Sonicwall

Sonicos

79 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 3.44%
  • Veröffentlicht 23.08.2024 07:15:03
  • Zuletzt bearbeitet 31.10.2025 15:56:26

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firew...

  • EPSS 10.16%
  • Veröffentlicht 18.07.2024 08:15:02
  • Zuletzt bearbeitet 21.11.2024 09:31:34

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

Medienbericht
  • EPSS 22.16%
  • Veröffentlicht 09.07.2024 12:15:20
  • Zuletzt bearbeitet 12.05.2026 12:16:57

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Respon...

  • EPSS 2.28%
  • Veröffentlicht 20.06.2024 09:15:11
  • Zuletzt bearbeitet 25.03.2025 17:15:53

Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.

  • EPSS 2.25%
  • Veröffentlicht 20.06.2024 09:15:11
  • Zuletzt bearbeitet 25.03.2025 17:15:53

Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

  • EPSS 0.23%
  • Veröffentlicht 14.03.2024 04:15:09
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.

  • EPSS 1.42%
  • Veröffentlicht 14.03.2024 04:15:09
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

  • EPSS 0.96%
  • Veröffentlicht 08.02.2024 02:15:07
  • Zuletzt bearbeitet 21.11.2024 08:56:11

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

  • EPSS 0.29%
  • Veröffentlicht 17.10.2023 23:15:12
  • Zuletzt bearbeitet 21.11.2024 08:21:31

SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.

  • EPSS 0.48%
  • Veröffentlicht 17.10.2023 23:15:12
  • Zuletzt bearbeitet 21.11.2024 08:21:31

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.