← Back

Sonicwall

sonicwall

229 CVEs • 352 products

Products (352)

Click to collapse
Toggle
Sonicos
sonicos
Sonicosv
sonicosv
Analytics
analytics
Analyzer
analyzer
Netextender
netextender
Sma8200v
sma8200v
Scrutinizer
scrutinizer
Ssl Vpn
ssl_vpn
Sma 500v
sma_500v
Soho Firewall
soho_firewall
Soho Firmware
soho_firmware
Uma Em5000
uma_em5000
Viewpoint
viewpoint

CVEs (229)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
1Sonicos
Jun 17, 2026
Nov 20, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
1Sonicwall
3Sma 210 Firmware
Sma 410 FirmwareSma 500v Firmware
Jun 17, 2026
Oct 31, 2025
N/A· v4
4.5 MEDIUM· v3
N/A· v2
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
1Sonicwall
1Sonicos
Jun 17, 2026
Jul 29, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
1Sonicwall
3Sma 210 Firmware
Sma 410 FirmwareSma 500v Firmware
Jun 17, 2026
Jul 23, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.
1Sonicwall
3Sma 210 Firmware
Sma 410 FirmwareSma 500v Firmware
Jun 17, 2026
Jul 23, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
1Sonicwall
3Sma 210 Firmware
Sma 410 FirmwareSma 500v Firmware
Jun 17, 2026
Jul 23, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
1Sonicwall
3Sma 210 Firmware
Sma 410 FirmwareSma 500v Firmware
Jun 17, 2026
Jul 23, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system,...Show more
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.Show less
1Sonicwall
6Sma 100 Firmware
Sma 200 FirmwareSma 210 Firmware+3 more
Jun 17, 2026
May 7, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
1Sonicwall
6Sma 100 Firmware
Sma 200 FirmwareSma 210 Firmware+3 more
Jun 17, 2026
May 7, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
1Sonicwall
6Sma 100 Firmware
Sma 200 FirmwareSma 210 Firmware+3 more
Jun 17, 2026
May 7, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
1Sonicwall
1Sma1000 Firmware
Jun 17, 2026
Apr 30, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the a...Show more
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.Show less
1Sonicwall
8Sma6200 Firmware
Sma6210 FirmwareSma7200 Firmware+5 more
Jun 17, 2026
Jan 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentiall...Show more
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.Show less
1Sonicwall
1Sonicos
Jun 17, 2026
Jan 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Jun 17, 2026
Dec 5, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially...Show more
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.Show less
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Jun 17, 2026
Dec 5, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the gen...Show more
Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.Show less
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Jun 17, 2026
Dec 5, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Jun 17, 2026
Dec 5, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Jun 17, 2026
Dec 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
1Sonicwall
1Sonicos
Jun 17, 2026
Aug 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This...Show more
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.Show less
1Sonicwall
1Sonicos
Jun 17, 2026
Jul 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).