CVE-2023-41712
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:31
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.
CVE-2023-41715
- EPSS 0.34%
- Veröffentlicht 17.10.2023 23:15:12
- Zuletzt bearbeitet 02.05.2025 19:15:55
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
CVE-2023-39280
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:03
SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.
CVE-2023-39279
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:03
SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.
CVE-2023-39278
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:02
SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.
CVE-2023-39277
- EPSS 0.48%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:02
SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.
CVE-2023-39276
- EPSS 0.63%
- Veröffentlicht 17.10.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:02
SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
CVE-2023-1101
- EPSS 0.35%
- Veröffentlicht 02.03.2023 22:15:09
- Zuletzt bearbeitet 07.03.2025 20:15:36
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
CVE-2023-0656
- EPSS 31.49%
- Veröffentlicht 02.03.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:34
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
CVE-2022-22275
- EPSS 0.26%
- Veröffentlicht 27.04.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:46:32
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.