Vulnerabilities
Vulnerable Software
Sonicwall:  Security Vulnerabilities
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.
CVSS Score
3.8
EPSS Score
0.003
Published
2026-03-31
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
CVSS Score
4.8
EPSS Score
0.002
Published
2026-03-31
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.
CVSS Score
4.9
EPSS Score
0.003
Published
2026-03-04
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
CVSS Score
4.9
EPSS Score
0.004
Published
2026-02-24
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
CVSS Score
4.9
EPSS Score
0.003
Published
2026-02-24
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
CVSS Score
4.9
EPSS Score
0.003
Published
2026-02-24
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.
CVSS Score
4.9
EPSS Score
0.003
Published
2026-02-24
CVE-2025-40602
Known exploited
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
CVSS Score
6.6
EPSS Score
0.02
Published
2025-12-18
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
CVSS Score
7.5
EPSS Score
0.012
Published
2025-11-20
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-11-20


Contact Us

Shodan ® - All rights reserved