Products

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
SonicWall vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:SonicWall Email Security Restricted CLI OS Command Injection via SNMP

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.

CWE-94Aug 11, 2026
CVSS7.8v3.1EPSS0.199%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall Email Security OS Command Injection via Netmask in Restricted CLI

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

CWE-94Aug 11, 2026
CVSS7.8v3.1EPSS0.199%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall GMS Insecure Deserialization Vulnerability

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

CWE-502Aug 11, 2026
CVSS8.4v3.1EPSS0.221%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall GMS Improper Certificate Validation

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

CWE-295Aug 11, 2026
CVSS8.3v3.1EPSS0.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall GMS Command-Line Interface Authenticated Command Injection

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

CWE-94Aug 11, 2026
CVSS6.3v3.1EPSS1.17%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall GMS Dispatcher Service Command Injection

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

CWE-94Aug 11, 2026
CVSS9.4v3.1EPSS1.05%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall GMS Cross-Site Scripting

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.

CWE-79Aug 11, 2026
CVSS6.1v3.1EPSS0.264%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall GMS Unauthenticated Remote Code Execution via ZipSlip

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

CWE-94Aug 11, 2026
CVSS9.1v3.1EPSS0.434%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall Global VPN Client SWIPsec.sys Driver Out-of-Bounds Kernel Memory Read

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

CWE-125Aug 7, 2026
CVSS5.5v3.1EPSS0.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS HTTP Header Manipulation Vulnerability

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

CWE-644Aug 5, 2026
CVSS6.5v3.1EPSS0.205%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall SMA1000 Appliances Code Injection Vulnerability

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CWE-94Jul 14, 2026
CVSS7.2v3.1EPSS76.3%PoCs3SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CWE-918Jul 14, 20261 related artifact
CVSS10.0v3.1EPSS74.2%PoCs7SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow Vulnerability

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

CWE-121Apr 29, 2026
CVSS4.9v3.1EPSS0.504%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Path Traversal Vulnerability

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

CWE-35Apr 29, 2026
CVSS6.8v3.1EPSS0.428%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Access Control Weak Authentication Vulnerability

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

CWE-1390CWE-306Apr 29, 2026
CVSS8.0v3.1EPSS0.417%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall SMA1000 Improper Handling of Unicode Encoding Authentication Bypass

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

CWE-176Apr 9, 2026
CVSS7.2v3.1EPSS0.417%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall SMA1000 Improper Handling of Unicode Encoding Authentication Bypass

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

CWE-176Apr 9, 2026
CVSS6.6v3.1EPSS0.597%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall SMA1000 Observable Response Discrepancy Enables SSL VPN User Credential Enumeration

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

CWE-204Apr 9, 2026
CVSS7.2v3.1EPSS0.363%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall SMA1000 SQL Injection Privilege Escalation

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.

CWE-89Apr 9, 2026
CVSS7.2v3.1EPSS0.613%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall Email Security Improper Input Validation

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.

CWE-20Mar 31, 2026
CVSS3.8v3.1EPSS0.321%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall Email Security Denial of Service via Improper Input Validation

A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

CWE-20Mar 31, 2026
CVSS2.7v3.1EPSS0.386%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicWall Email Security Stored Cross-Site Scripting

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

CWE-79Mar 31, 2026
CVSS4.8v3.1EPSS0.226%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow in Certificate Handling

A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

CWE-121Mar 4, 2026
CVSS4.9v3.1EPSS0.259%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Out-of-Bounds Read Vulnerability

A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

CWE-125Feb 24, 2026
CVSS4.9v3.1EPSS0.342%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication NULL Pointer Dereference Denial of Service

A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

CWE-476Feb 24, 2026
CVSS4.9v3.1EPSS0.342%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX