SonicWall Vulnerabilities and Affected Products
Vulnerabilities associated with SonicWall Global VPN Client.
Products
Clear product- SonicOS68 vulnerabilities
- SMA10026 vulnerabilities
- GMS24 vulnerabilities
- Analytics15 vulnerabilities
- SMA100013 vulnerabilities
- Email Security11 vulnerabilities
- SonicWall SMA10011 vulnerabilities
- NetExtender9 vulnerabilities
- SonicOSv5 vulnerabilities
- SonicWall Email Security5 vulnerabilities
- SonicWall Global VPN Client5 vulnerabilities
- SMA 100 Series4 vulnerabilities
- sma100_firmware4 vulnerabilities
- SonicWall SMA10004 vulnerabilities
- Connect Tunnel3 vulnerabilities
- Global Management System (GMS)3 vulnerabilities
- global_management_system3 vulnerabilities
- SMA1000 Appliances3 vulnerabilities
- sma_200_firmware3 vulnerabilities
- SonicWall SRA/SMA1003 vulnerabilities
- Directory Services Connector2 vulnerabilities
- Email Security Appliance2 vulnerabilities
- SMA100 Appliances2 vulnerabilities
- SonicWall Analytics On-Prem2 vulnerabilities
- SonicWall GMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-20051HIGH | SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system. CWE-427May 4, 2022 | CVSS7.8v3.1 | EPSS0.697% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20047HIGH | SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system. CWE-427Dec 8, 2021 | CVSS7.8v3.1 | EPSS0.851% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20037HIGH | SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This vulnerability impacts GVC 4.10.5 installer and earlier. CWE-276Sep 21, 2021 | CVSS7.8v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-5144HIGH | SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability. CWE-426Oct 28, 2020 | CVSS7.8v3.1 | EPSS0.576% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-5145HIGH | SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system. CWE-427Oct 28, 2020 | CVSS8.6v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |