CVE-2025-32821
- EPSS 0.2%
- Veröffentlicht 07.05.2025 17:22:14
- Zuletzt bearbeitet 19.05.2025 15:12:23
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
CVE-2025-32820
- EPSS 0.57%
- Veröffentlicht 07.05.2025 17:20:10
- Zuletzt bearbeitet 19.05.2025 15:12:48
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
CVE-2025-32819
- EPSS 0.34%
- Veröffentlicht 07.05.2025 17:18:23
- Zuletzt bearbeitet 19.05.2025 15:13:46
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
CVE-2021-20049
- EPSS 0.45%
- Veröffentlicht 23.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 05:45:51
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
CVE-2021-20050
- EPSS 0.22%
- Veröffentlicht 23.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 05:45:51
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
CVE-2021-20016
- EPSS 80.45%
- Veröffentlicht 04.02.2021 06:15:13
- Zuletzt bearbeitet 14.03.2025 17:00:01
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x...
- EPSS 2.26%
- Veröffentlicht 09.01.2021 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:37
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.
CVE-2019-7486
- EPSS 0.68%
- Veröffentlicht 19.12.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:48:16
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
CVE-2019-7482
- EPSS 64.58%
- Veröffentlicht 19.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:48:15
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
CVE-2019-7483
- EPSS 39.94%
- Veröffentlicht 19.12.2019 01:15:10
- Zuletzt bearbeitet 14.03.2025 17:40:32
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.