Sonicwall

Sma1000

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 09.04.2026 14:27:29
  • Zuletzt bearbeitet 14.05.2026 19:33:35

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

  • EPSS 0.04%
  • Veröffentlicht 09.04.2026 14:25:41
  • Zuletzt bearbeitet 14.05.2026 19:37:22

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

  • EPSS 0.1%
  • Veröffentlicht 09.04.2026 14:23:53
  • Zuletzt bearbeitet 14.05.2026 19:37:45

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

Medienbericht
  • EPSS 0.03%
  • Veröffentlicht 09.04.2026 14:22:21
  • Zuletzt bearbeitet 14.05.2026 19:43:40

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator...

Warnung
  • EPSS 0.15%
  • Veröffentlicht 18.12.2025 10:58:41
  • Zuletzt bearbeitet 19.12.2025 13:57:43

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Medienbericht
  • EPSS 0.09%
  • Veröffentlicht 14.05.2025 16:35:54
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended loca...

  • EPSS 0.1%
  • Veröffentlicht 30.04.2025 18:46:34
  • Zuletzt bearbeitet 14.05.2025 17:15:47

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to a...

  • EPSS 0.18%
  • Veröffentlicht 11.10.2024 13:15:16
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.