Showing 25 vulnerabilities on this page for SonicOS

Signals CISA KEV Ransomware Nuclei
SonicWall vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:SonicOS HTTP Header Manipulation Vulnerability

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

CWE-644Aug 5, 2026
CVSS6.5v3.1EPSS0.205%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow Vulnerability

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

CWE-121Apr 29, 2026
CVSS4.9v3.1EPSS0.504%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Path Traversal Vulnerability

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

CWE-35Apr 29, 2026
CVSS6.8v3.1EPSS0.428%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Access Control Weak Authentication Vulnerability

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

CWE-1390CWE-306Apr 29, 2026
CVSS8.0v3.1EPSS0.417%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow in Certificate Handling

A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

CWE-121Mar 4, 2026
CVSS4.9v3.1EPSS0.259%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Out-of-Bounds Read Vulnerability

A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

CWE-125Feb 24, 2026
CVSS4.9v3.1EPSS0.342%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication NULL Pointer Dereference Denial of Service

A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

CWE-476Feb 24, 2026
CVSS4.9v3.1EPSS0.342%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Post-Authentication Format String Vulnerability

A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

CWE-134Feb 24, 2026
CVSS4.9v3.1EPSS0.425%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SonicOS Management Interface Post-Authentication Stack-Based Buffer Overflow

Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.

CWE-121Feb 24, 2026
CVSS4.9v3.1EPSS0.322%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall sonicos Stack-based Buffer Overflow

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

CWE-121Nov 20, 2025
CVSS7.5v3.1EPSS1.15%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall sonicos Use of Externally-Controlled Format String

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

CWE-134Jul 29, 2025
CVSS9.8v3.1EPSS0.875%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall sonicos NULL Pointer Dereference

A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

CWE-476Apr 23, 2025
CVSS7.5v3.1EPSS0.822%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall sonicos Authentication Bypass by Primary Weakness

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.

CWE-305Jan 9, 2025
CVSS9.1v3.1EPSS0.497%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

CWE-37Jan 9, 2025
CVSS4.9v3.1EPSS0.641%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

CWE-134Jan 9, 2025
CVSS7.2v3.1EPSS0.709%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

CWE-121Jan 9, 2025
CVSS7.2v3.1EPSS0.805%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

CWE-190Jan 9, 2025
CVSS9.8v3.1EPSS0.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.

CWE-269Jan 9, 2025
CVSS7.8v3.1EPSS0.339%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall sonicos Server-Side Request Forgery (SSRF)

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

CWE-918Jan 9, 2025
CVSS7.5v3.1EPSS0.737%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CWE-287Jan 9, 20251 related artifact
CVSS9.8v3.1EPSS95.1%PoCs3SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

SonicWall sonicos Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

CWE-338Jan 9, 2025
CVSS9.8v3.1EPSS1.04%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall SonicOS Improper Access Control Vulnerability

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CWE-284Aug 23, 2024
CVSS9.8v3.1EPSS18.2%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

CWE-122CWE-787Jul 18, 2024
CVSS7.5v3.1EPSS0.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.

CWE-122CWE-787Jun 20, 2024
CVSS6.5v3.1EPSS0.638%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

CWE-121CWE-787Jun 20, 2024
CVSS7.5v3.1EPSS0.539%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX