Sonicwall Sonicos vulnerabilities

77 known vulnerabilities affecting sonicwall/sonicos.

Total CVEs
77
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH32MEDIUM31

Vulnerabilities

Page 2 of 4
CVE-2024-29013MEDIUMCVSS 6.5fixed in 7.0.1-5161≥ 7.1.1, < 7.1.1-7058+2 more2024-06-20
CVE-2024-29013 [MEDIUM] CWE-122 CVE-2024-29013: Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attac Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
cvelistv5nvd
CVE-2024-22397HIGHCVSS 8.3v7.0.1-5145 and earlier versionsv7.1.1-7047 and earlier versions2024-03-14
CVE-2024-22397 [HIGH] CWE-79 CVE-2024-22397: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.
cvelistv5nvd
CVE-2024-22396MEDIUMCVSS 5.3v7.0.1-5145 and earlier versionsv7.1.1-7047 and earlier versions+2 more2024-03-14
CVE-2024-22396 [MEDIUM] CWE-190 CVE-2024-22396: An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
cvelistv5nvd
CVE-2024-22394CRITICALCVSS 9.8v7.1.1-7040vSonicOS 7.1.1-70402024-02-08
CVE-2024-22394 [CRITICAL] CWE-287 CVE-2024-22394: An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, w An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040.
cvelistv5nvd
CVE-2023-41715HIGHCVSS 8.8fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-41715 [HIGH] CWE-269 CVE-2023-41715: SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunne SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
cvelistv5nvd
CVE-2023-41713HIGHCVSS 7.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-41713 [HIGH] CWE-259 CVE-2023-41713: SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
cvelistv5nvd
CVE-2023-39276MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-39276 [MEDIUM] CWE-121 CVE-2023-39276: SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json U SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
cvelistv5nvd
CVE-2023-39279MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-39279 [MEDIUM] CWE-121 CVE-2023-39279: SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.jso SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.
cvelistv5nvd
CVE-2023-39280MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-39280 [MEDIUM] CWE-121 CVE-2023-39280: SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoSt SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.
cvelistv5nvd
CVE-2023-41712MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-41712 [MEDIUM] CWE-121 CVE-2023-41712: SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.
cvelistv5nvd
CVE-2023-39277MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-39277 [MEDIUM] CWE-121 CVE-2023-39277: SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appf SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.
cvelistv5nvd
CVE-2023-39278MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-39278 [MEDIUM] CWE-121 CVE-2023-39278: SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerabilit SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.
cvelistv5nvd
CVE-2023-41711MEDIUMCVSS 6.5fixed in 7.0.1-5145fixed in 6.5.4.4-44v-21-2340+5 more2023-10-17
CVE-2023-41711 [MEDIUM] CWE-121 CVE-2023-41711: SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.ex SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.
cvelistv5nvd
CVE-2023-1101HIGHCVSS 8.8fixed in 7.0.1-5111≤ 7.0.1-5083+6 more2023-03-02
CVE-2023-1101 [HIGH] CWE-307 CVE-2023-1101: SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
cvelistv5nvd
CVE-2023-0656HIGHCVSS 7.5≤ 7.0.1-5111≤ 7.0.1-5083+4 more2023-03-02
CVE-2023-0656 [HIGH] CWE-121 CVE-2023-0656: A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
cvelistv5nvd
CVE-2022-22275HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.1-5030-r2007≥ 7.0.0.0, ≤ 7.0.1.0-5030-1391+5 more2022-04-27
CVE-2022-22275 [HIGH] CWE-400 CVE-2022-22275: Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassin Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.
cvelistv5nvd
CVE-2022-22278HIGHCVSS 7.5vSonicOS Gen 7 TZ-Series 7.0.1-5030-R2007 and earlier versions.vSonicOS Gen 7 NSa-Series 7.0.1-5030-R2007 and earlier versions.+2 more2022-04-27
CVE-2022-22278 [HIGH] CWE-770 CVE-2022-22278: A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP respon A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack
cvelistv5nvd
CVE-2022-22276MEDIUMCVSS 5.3vSonicOS Gen 7 TZ-Series 7.0.1-5030-R2007 and earlier versions.vSonicOS Gen 7 NSa-Series 7.0.1-5030-R2007 and earlier versions.+2 more2022-04-27
CVE-2022-22276 [MEDIUM] CWE-200 CVE-2022-22276: A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthoriz A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
cvelistv5nvd
CVE-2022-22277MEDIUMCVSS 5.3vSonicOS Gen 7 TZ-Series 7.0.1-5030-R2007 and earlier versions.vSonicOS Gen 7 NSa-Series 7.0.1-5030-R2007 and earlier versions.+3 more2022-04-27
CVE-2022-22277 [MEDIUM] CWE-200 CVE-2022-22277: A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive inform A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
cvelistv5nvd
CVE-2022-22274CRITICALCVSS 9.8≤ 7.0.1-5050≤ 7.0.1-r579+3 more2022-03-25
CVE-2022-22274 [CRITICAL] CWE-121 CVE-2022-22274: A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthen A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
cvelistv5nvd
Sonicwall Sonicos vulnerabilities | cvebase