SonicWall Vulnerabilities and Affected Products
Vulnerabilities associated with sma100_firmware.
Products
Clear product- SonicOS68 vulnerabilities
- SMA10026 vulnerabilities
- GMS24 vulnerabilities
- Analytics15 vulnerabilities
- SMA100013 vulnerabilities
- Email Security11 vulnerabilities
- SonicWall SMA10011 vulnerabilities
- NetExtender9 vulnerabilities
- SonicOSv5 vulnerabilities
- SonicWall Email Security5 vulnerabilities
- SonicWall Global VPN Client5 vulnerabilities
- SMA 100 Series4 vulnerabilities
- sma100_firmware4 vulnerabilities
- SonicWall SMA10004 vulnerabilities
- Connect Tunnel3 vulnerabilities
- Global Management System (GMS)3 vulnerabilities
- global_management_system3 vulnerabilities
- SMA1000 Appliances3 vulnerabilities
- sma_200_firmware3 vulnerabilities
- SonicWall SRA/SMA1003 vulnerabilities
- Directory Services Connector2 vulnerabilities
- Email Security Appliance2 vulnerabilities
- SMA100 Appliances2 vulnerabilities
- SonicWall Analytics On-Prem2 vulnerabilities
- SonicWall GMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-53703HIGH | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution. CWE-121Dec 5, 2024 | CVSS8.1v3.1 | EPSS12.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-53702MEDIUM | Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret. CWE-338Dec 5, 2024 | CVSS5.3v3.1 | EPSS0.341% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45318HIGH | A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution. CWE-121Dec 5, 2024 | CVSS8.1v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-40763HIGH | Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution. CWE-122Dec 5, 2024 | CVSS7.5v3.1 | EPSS0.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |