SonicWall Vulnerabilities and Affected Products
Vulnerabilities associated with SonicOS.
Products
Clear product- SonicOS68 vulnerabilities
- SMA10026 vulnerabilities
- GMS24 vulnerabilities
- Analytics15 vulnerabilities
- SMA100013 vulnerabilities
- Email Security11 vulnerabilities
- SonicWall SMA10011 vulnerabilities
- NetExtender9 vulnerabilities
- SonicOSv5 vulnerabilities
- SonicWall Email Security5 vulnerabilities
- SonicWall Global VPN Client5 vulnerabilities
- SMA 100 Series4 vulnerabilities
- sma100_firmware4 vulnerabilities
- SonicWall SMA10004 vulnerabilities
- Connect Tunnel3 vulnerabilities
- Global Management System (GMS)3 vulnerabilities
- global_management_system3 vulnerabilities
- SMA1000 Appliances3 vulnerabilities
- sma_200_firmware3 vulnerabilities
- SonicWall SRA/SMA1003 vulnerabilities
- Directory Services Connector2 vulnerabilities
- Email Security Appliance2 vulnerabilities
- SMA100 Appliances2 vulnerabilities
- SonicWall Analytics On-Prem2 vulnerabilities
- SonicWall GMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-0516MEDIUM | Generated title:SonicOS HTTP Header Manipulation VulnerabilityA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. CWE-644Aug 5, 2026 | CVSS6.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0206MEDIUM | Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow VulnerabilityA post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. CWE-121Apr 29, 2026 | CVSS4.9v3.1 | EPSS0.504% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0205MEDIUM | Generated title:SonicOS Post-Authentication Path Traversal VulnerabilityA post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. CWE-35Apr 29, 2026 | CVSS6.8v3.1 | EPSS0.428% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0204HIGH | Generated title:SonicOS Access Control Weak Authentication VulnerabilityA vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | CVSS8.0v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3439MEDIUM | Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow in Certificate HandlingA post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. CWE-121Mar 4, 2026 | CVSS4.9v3.1 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0402MEDIUM | Generated title:SonicOS Post-Authentication Out-of-Bounds Read VulnerabilityA post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. CWE-125Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0401MEDIUM | Generated title:SonicOS Post-Authentication NULL Pointer Dereference Denial of ServiceA post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0400MEDIUM | Generated title:SonicOS Post-Authentication Format String VulnerabilityA post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. CWE-134Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.425% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0399MEDIUM | Generated title:SonicOS Management Interface Post-Authentication Stack-Based Buffer OverflowMultiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. CWE-121Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-40601HIGH | SonicWall sonicos Stack-based Buffer OverflowA Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. CWE-121Nov 20, 2025 | CVSS7.5v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-40600CRITICAL | SonicWall sonicos Use of Externally-Controlled Format StringUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. CWE-134Jul 29, 2025 | CVSS9.8v3.1 | EPSS0.875% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32818HIGH | SonicWall sonicos NULL Pointer DereferenceA Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition. CWE-476Apr 23, 2025 | CVSS7.5v3.1 | EPSS0.822% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12802CRITICAL | SonicWall sonicos Authentication Bypass by Primary WeaknessSSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name. CWE-305Jan 9, 2025 | CVSS9.1v3.1 | EPSS0.497% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2024-12806MEDIUM | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file. CWE-37Jan 9, 2025 | CVSS4.9v3.1 | EPSS0.641% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12805HIGH | A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. CWE-134Jan 9, 2025 | CVSS7.2v3.1 | EPSS0.709% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12803HIGH | A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. CWE-121Jan 9, 2025 | CVSS7.2v3.1 | EPSS0.805% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-40765CRITICAL | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. CWE-190Jan 9, 2025 | CVSS9.8v3.1 | EPSS0.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-53706HIGH | A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution. CWE-269Jan 9, 2025 | CVSS7.8v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-53705HIGH | SonicWall sonicos Server-Side Request Forgery (SSRF)A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall. CWE-918Jan 9, 2025 | CVSS7.5v3.1 | EPSS0.737% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-53704CRITICAL | SonicWall SonicOS SSLVPN Improper Authentication VulnerabilityAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | CVSS9.8v3.1 | EPSS95.1% | PoCs3 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2024-40762CRITICAL | SonicWall sonicos Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass. CWE-338Jan 9, 2025 | CVSS9.8v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-40766CRITICAL | SonicWall SonicOS Improper Access Control VulnerabilityAn improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. CWE-284Aug 23, 2024 | CVSS9.8v3.1 | EPSS18.2% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2024-40764HIGH | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). | CVSS7.5v3.1 | EPSS0.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29013MEDIUM | Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function. | CVSS6.5v3.1 | EPSS0.638% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29012HIGH | Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function. | CVSS7.5v3.1 | EPSS0.539% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |