Sonicwall
348 known vulnerabilities
Top Products
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewal
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to dat
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security applianc
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to i
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to impr
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulne
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. Th
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to a
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not pu
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This
Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. Th
Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using view
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user t
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function lib
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vu
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET se
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vuln
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: Do
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPN
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security v
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulner
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: St
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using e
A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext da
A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivi
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unsta
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management S
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` modu
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV D
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
Frequently Asked Questions
How many CVEs affect Sonicwall?
Sonicwall has 348 CVE records in our database, including 25 critical and 71 high severity vulnerabilities. 4 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Sonicwall vulnerabilities?
Sonicwall has 25 critical severity (CVSS 9.0+) and 71 high severity (CVSS 7.0-8.9) vulnerabilities. 4 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Sonicwall vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Sonicwall products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Sonicwall Vulnerabilities
CyberStrike scans your infrastructure for Sonicwall vulnerabilities and provides real-time remediation guidance.
Get Started