CVE-2023-39279
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:03
SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.
CVE-2023-39278
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:02
SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.
CVE-2023-39277
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:02
SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.
CVE-2023-39276
- EPSS 0.63%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:02
SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
CVE-2023-1101
- EPSS 0.44%
- Veröffentlicht 02.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 20:15:36
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
CVE-2023-0656
- EPSS 31.49%
- Veröffentlicht 02.03.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:34
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
CVE-2022-22275
- EPSS 0.26%
- Veröffentlicht 27.04.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:46:32
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.
CVE-2022-22274
- EPSS 47%
- Veröffentlicht 25.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:32
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
CVE-2021-20048
- EPSS 1.37%
- Veröffentlicht 10.01.2022 14:10:16
- Zuletzt bearbeitet 21.11.2024 05:45:51
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, ...
CVE-2021-20046
- EPSS 1.37%
- Veröffentlicht 10.01.2022 14:10:16
- Zuletzt bearbeitet 21.11.2024 05:45:50
A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Ge...