SonicWall Vulnerabilities and Affected Products
Vulnerabilities associated with NetExtender.
Products
Clear product- SonicOS68 vulnerabilities
- SMA10026 vulnerabilities
- GMS24 vulnerabilities
- Analytics15 vulnerabilities
- SMA100013 vulnerabilities
- Email Security11 vulnerabilities
- SonicWall SMA10011 vulnerabilities
- NetExtender9 vulnerabilities
- SonicOSv5 vulnerabilities
- SonicWall Email Security5 vulnerabilities
- SonicWall Global VPN Client5 vulnerabilities
- SMA 100 Series4 vulnerabilities
- sma100_firmware4 vulnerabilities
- SonicWall SMA10004 vulnerabilities
- Connect Tunnel3 vulnerabilities
- Global Management System (GMS)3 vulnerabilities
- global_management_system3 vulnerabilities
- SMA1000 Appliances3 vulnerabilities
- sma_200_firmware3 vulnerabilities
- SonicWall SRA/SMA1003 vulnerabilities
- Directory Services Connector2 vulnerabilities
- Email Security Appliance2 vulnerabilities
- SMA100 Appliances2 vulnerabilities
- SonicWall Analytics On-Prem2 vulnerabilities
- SonicWall GMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-23010HIGH | An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths. CWE-59Apr 10, 2025 | CVSS7.2v3.1 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-23009HIGH | A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion. CWE-250Apr 10, 2025 | CVSS7.2v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-23008HIGH | An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker to modify configurations. CWE-250Apr 10, 2025 | CVSS7.2v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-23007MEDIUM | A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation. | CVSS5.5v3.1 | EPSS0.194% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29014HIGH | Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update. CWE-94Jul 18, 2024 | CVSS8.8v3.1 | EPSS1.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6340MEDIUM | SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability. | CVSS5.5v3.1 | EPSS0.213% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-44220HIGH | SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system. CWE-427Oct 27, 2023 | CVSS7.3v3.1 | EPSS0.294% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-44218HIGH | A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability. CWE-267Oct 3, 2023 | CVSS8.8v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-44217HIGH | A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality. CWE-269Oct 3, 2023 | CVSS7.8v3.1 | EPSS0.178% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |