Sonicwall
sonicwall
231 CVEs • 352 products
Products (352)
Click to collapseToggle
Products (352)
Click to collapse
CVEs (231)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sonicwall 3Sma6210 Firmware Sma7210 FirmwareSma8200vSep 3, 2026 Sep 1, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditi...Show more |
1Sonicwall 3Sma6210 Firmware Sma7210 FirmwareSma8200vSep 3, 2026 Sep 1, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to g...Show more |
1Sonicwall 3Sma6210 Firmware Sma7210 FirmwareSma8200vJul 16, 2026 Jul 14, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a re...Show more |
1Sonicwall 3Sma6210 Firmware Sma7210 FirmwareSma8200vJul 16, 2026 Jul 14, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended...Show more |
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. |
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. |
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. |
1Sonicwall 5Sma6200 Firmware Sma6210 FirmwareSma7200 Firmware+2 moreJun 17, 2026 Apr 9, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. |
1Sonicwall 5Sma6200 Firmware Sma6210 FirmwareSma7200 Firmware+2 moreJun 17, 2026 Apr 9, 2026 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. |
1Sonicwall 5Sma6200 Firmware Sma6210 FirmwareSma7200 Firmware+2 moreJun 17, 2026 Apr 9, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials. |
1Sonicwall 5Sma6200 Firmware Sma6210 FirmwareSma7200 Firmware+2 moreJun 17, 2026 Apr 9, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privi...Show more |
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by pro...Show more |
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unrespo...Show more |
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenti...Show more |
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. |
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. |
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. |
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. |
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. |
1Sonicwall 5Sma6200 Firmware Sma6210 FirmwareSma7200 Firmware+2 moreJun 17, 2026 Dec 18, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |