Sonicwall Sma100 vulnerabilities

26 known vulnerabilities affecting sonicwall/sma100.

Total CVEs
26
CISA KEV
4
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH16MEDIUM8

Vulnerabilities

Page 1 of 2
CVE-2025-40603MEDIUMCVSS 4.5v10.2.2.2-92sv and earlier versions2025-10-31
CVE-2025-40603 [MEDIUM] CWE-532 CVE-2025-40603: A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
cvelistv5nvd
CVE-2025-32821HIGHCVSS 7.2v10.2.1.14-75sv and earlier versions2025-05-07
CVE-2025-32821 [HIGH] CWE-78 CVE-2025-32821: A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can wi A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
cvelistv5nvd
CVE-2025-32820HIGHCVSS 8.8v10.2.1.14-75sv and earlier versions2025-05-07
CVE-2025-32820 [HIGH] CWE-22 CVE-2025-32820: A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inj A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
cvelistv5nvd
CVE-2025-32819HIGHCVSS 8.8v10.2.1.14-75sv and earlier versions2025-05-07
CVE-2025-32819 [HIGH] CWE-552 CVE-2025-32819: A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypa A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
cvelistv5nvd
CVE-2024-40763HIGHCVSS 7.5v10.2.1.13-72sv and earlier versions2024-12-05
CVE-2024-40763 [HIGH] CWE-122 CVE-2024-40763: Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. Th Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
cvelistv5nvd
CVE-2024-53703HIGHCVSS 8.1v10.2.1.13-72sv and earlier versions2024-12-05
CVE-2024-53703 [HIGH] CWE-121 CVE-2024-53703: A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_http A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
cvelistv5nvd
CVE-2024-45318HIGHCVSS 8.1v10.2.1.13-72sv and earlier versions2024-12-05
CVE-2024-45318 [HIGH] CWE-121 CVE-2024-45318: A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to c A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
cvelistv5nvd
CVE-2024-45319MEDIUMCVSS 6.3v10.2.1.13-72sv and earlier versions2024-12-05
CVE-2024-45319 [MEDIUM] CWE-798 CVE-2024-45319: A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.
cvelistv5nvd
CVE-2024-53702MEDIUMCVSS 5.3v10.2.1.13-72sv and earlier versions2024-12-05
CVE-2024-53702 [MEDIUM] CWE-338 CVE-2024-53702: Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall S Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.
cvelistv5nvd
CVE-2024-22395MEDIUMCVSS 6.3v10.2.1.10-62sv and earlier versions2024-02-24
CVE-2024-22395 [MEDIUM] CWE-287 CVE-2024-22395: Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office porta Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
cvelistv5nvd
CVE-2023-5970HIGHCVSS 8.8v10.2.1.9-57sv and earlier versions2023-12-05
CVE-2023-5970 [HIGH] CWE-287 CVE-2023-5970: Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated at Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
cvelistv5nvd
CVE-2023-44221HIGHCVSS 7.2KEVv10.2.1.9-57sv and earlier versions2023-12-05
CVE-2023-44221 [HIGH] CWE-78 CVE-2023-44221: Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remo Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
cvelistv5nvd
CVE-2022-2915HIGHCVSS 8.8v10.2.1.5-34sv and earlier2022-08-26
CVE-2022-2915 [HIGH] CWE-122 CVE-2022-2915: A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authent A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions.
cvelistv5nvd
CVE-2022-1703HIGHCVSS 8.8v10.2.1.4-31sv and earlierv10.2.0.9-41sv and earlier2022-06-08
CVE-2022-1703 [HIGH] CWE-78 CVE-2022-1703: Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interf Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.
cvelistv5nvd
CVE-2021-20034CRITICALCVSS 9.1PoCv9.0.0.10-28sv and earlierv10.2.0.7-34sv and earlier+1 more2021-09-27
CVE-2021-20034 [CRITICAL] CWE-284 CVE-2021-20034: An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypas An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
cvelistv5nvd
CVE-2021-20035MEDIUMCVSS 6.5KEVv9.0.0.10-28sv and earlierv10.2.0.7-34sv and earlier+1 more2021-09-27
CVE-2021-20035 [MEDIUM] CWE-78 CVE-2021-20035: Improper neutralization of special elements in the SMA100 management interface allows a remote authe Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
cvelistv5nvd
CVE-2021-20017HIGHCVSS 8.8v10.2.0.5 and earlier2021-03-13
CVE-2021-20017 [HIGH] CWE-78 CVE-2021-20017: A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated att A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
cvelistv5nvd
CVE-2021-20018MEDIUMCVSS 4.9v10.2.0.5 and earlier2021-03-13
CVE-2021-20018 [MEDIUM] CWE-200 CVE-2021-20018: A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuratio A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
cvelistv5nvd
CVE-2020-5146HIGHCVSS 7.2v10.2.0.2-20sv and earlier2021-01-09
CVE-2020-5146 [HIGH] CWE-78 CVE-2020-5146: A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS c A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.
cvelistv5nvd
CVE-2020-5132MEDIUMCVSS 5.3vSMA100 10.2.0.2-20sv2020-09-30
CVE-2020-5132 [MEDIUM] CWE-200 CVE-2020-5132: SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of
cvelistv5nvd