CVE-2024-29013
- EPSS 1.34%
- Veröffentlicht 20.06.2024 09:15:11
- Zuletzt bearbeitet 25.03.2025 17:15:53
Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
CVE-2024-29012
- EPSS 2.25%
- Veröffentlicht 20.06.2024 09:15:11
- Zuletzt bearbeitet 25.03.2025 17:15:53
Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.
CVE-2024-22397
- EPSS 0.2%
- Veröffentlicht 14.03.2024 04:15:09
- Zuletzt bearbeitet 27.03.2025 17:15:54
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.
CVE-2024-22396
- EPSS 1.22%
- Veröffentlicht 14.03.2024 04:15:09
- Zuletzt bearbeitet 21.11.2024 08:56:11
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
CVE-2024-22394
- EPSS 0.86%
- Veröffentlicht 08.02.2024 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:56:11
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040.
CVE-2023-41712
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:31
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.
CVE-2023-41711
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:31
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.
CVE-2023-41713
- EPSS 0.29%
- Veröffentlicht 17.10.2023 23:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:31
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
CVE-2023-41715
- EPSS 0.34%
- Veröffentlicht 17.10.2023 23:15:12
- Zuletzt bearbeitet 02.05.2025 19:15:55
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
CVE-2023-39280
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:03
SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.