Vulnerabilities
Vulnerable Software
Sonicwall:  Security Vulnerabilities
A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.
CVSS Score
7.8
EPSS Score
0.005
Published
2022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.
CVSS Score
9.8
EPSS Score
0.076
Published
2022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
CVSS Score
7.5
EPSS Score
0.046
Published
2022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.
CVSS Score
6.1
EPSS Score
0.089
Published
2022-05-13
SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system.
CVSS Score
7.8
EPSS Score
0.007
Published
2022-05-04
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-04-27
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
CVSS Score
5.3
EPSS Score
0.008
Published
2022-04-27
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
CVSS Score
5.3
EPSS Score
0.008
Published
2022-04-27
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack
CVSS Score
7.5
EPSS Score
0.009
Published
2022-04-27
A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions
CVSS Score
4.9
EPSS Score
0.011
Published
2022-04-13


Contact Us

Shodan ® - All rights reserved