Sonicwall Sma 410 Firmware vulnerabilities
34 known vulnerabilities affecting sonicwall/sma_410_firmware.
Total CVEs
34
CISA KEV
5
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH19MEDIUM7
Vulnerabilities
Page 1 of 2
CVE-2025-40603MEDIUMCVSS 4.5fixed in 10.2.2.32025-10-31
CVE-2025-40603 [MEDIUM] CWE-532 CVE-2025-40603: A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
nvd
CVE-2025-40599CRITICALCVSS 9.1fixed in 10.2.2.1-90sv2025-07-23
CVE-2025-40599 [CRITICAL] CWE-434 CVE-2025-40599: An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management int
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.
nvd
CVE-2025-40596HIGHCVSS 7.3fixed in 10.2.2.1-90sv2025-07-23
CVE-2025-40596 [HIGH] CWE-121 CVE-2025-40596: A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauth
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
nvd
CVE-2025-40597HIGHCVSS 7.5fixed in 10.2.2.1-90sv2025-07-23
CVE-2025-40597 [HIGH] CWE-122 CVE-2025-40597: A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthe
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
nvd
CVE-2025-40598MEDIUMCVSS 6.1fixed in 10.2.2.1-90sv2025-07-23
CVE-2025-40598 [MEDIUM] CWE-79 CVE-2025-40598: A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allo
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
nvd
CVE-2025-32821HIGHCVSS 7.2fixed in 10.2.1.15-81sv2025-05-07
CVE-2025-32821 [HIGH] CWE-78 CVE-2025-32821: A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can wi
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
nvd
CVE-2025-32820HIGHCVSS 8.8fixed in 10.2.1.15-81sv2025-05-07
CVE-2025-32820 [HIGH] CWE-22 CVE-2025-32820: A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inj
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
nvd
CVE-2025-32819HIGHCVSS 8.8fixed in 10.2.1.15-81sv2025-05-07
CVE-2025-32819 [HIGH] CWE-552 CVE-2025-32819: A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypa
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
nvd
CVE-2024-40763HIGHCVSS 7.5fixed in 10.2.1.14-75sv2024-12-05
CVE-2024-40763 [HIGH] CWE-122 CVE-2024-40763: Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. Th
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
nvd
CVE-2024-53703HIGHCVSS 8.1fixed in 10.2.1.14-75sv2024-12-05
CVE-2024-53703 [HIGH] CWE-121 CVE-2024-53703: A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_http
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
nvd
CVE-2024-45318HIGHCVSS 8.1fixed in 10.2.1.14-75sv2024-12-05
CVE-2024-45318 [HIGH] CWE-121 CVE-2024-45318: A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to c
A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
nvd
CVE-2024-45319MEDIUMCVSS 6.3fixed in 10.2.1.14-75sv2024-12-05
CVE-2024-45319 [MEDIUM] CWE-798 CVE-2024-45319: A vulnerability in the SonicWall SMA100 SSLVPN
firmware 10.2.1.13-72sv and earlier versions allows
A vulnerability in the SonicWall SMA100 SSLVPN
firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.
nvd
CVE-2024-53702MEDIUMCVSS 5.3fixed in 10.2.1.14-75sv2024-12-05
CVE-2024-53702 [MEDIUM] CWE-338 CVE-2024-53702: Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall S
Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.
nvd
CVE-2024-38475CRITICALCVSS 9.1KEVPoCfixed in 10.2.1.14-75sv2024-07-01
CVE-2024-38475 [CRITICAL] CWE-116 CVE-2024-38475: Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attack
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Substitutions in server context that use a backrefe
nvd
CVE-2024-22395MEDIUMCVSS 6.3fixed in 10.2.1.11-65sv2024-02-24
CVE-2024-22395 [MEDIUM] CWE-287 CVE-2024-22395: Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office porta
Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
nvd
CVE-2023-5970HIGHCVSS 8.8≤ 10.2.1.9-57sv2023-12-05
CVE-2023-5970 [HIGH] CWE-287 CVE-2023-5970: Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated at
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
nvd
CVE-2023-44221HIGHCVSS 7.2KEV≤ 10.2.1.9-57sv2023-12-05
CVE-2023-44221 [HIGH] CWE-78 CVE-2023-44221: Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remo
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
nvd
CVE-2022-2915HIGHCVSS 8.8≤ 10.2.1.5-34sv2022-08-26
CVE-2022-2915 [HIGH] CWE-122 CVE-2022-2915: A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authent
A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions.
nvd
CVE-2022-1703HIGHCVSS 8.8≤ 10.2.1.4-31sv≤ 10.2.0.9-41sv2022-06-08
CVE-2022-1703 [HIGH] CWE-78 CVE-2022-1703: Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interf
Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.
nvd
CVE-2022-22279MEDIUMCVSS 4.9fixed in 9.0.0.10-28sv2022-04-13
CVE-2022-22279 [MEDIUM] CWE-23 CVE-2022-22279: A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (
A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.
nvd
1 / 2Next →