sonicwall

250 tracked vulnerabilities.

CVE-2021-20026 HIGH
SonicWall Network Security Manager < 2.2.0-R10 - Authenticated OS Command Injection
May 27, 2021
CVSS 8.8
EPSS 0.03
CVE-2021-20025 HIGH
SonicWall Email Security Virtual Appliance < 10.0.9 - Use of Hard-coded Credentials
May 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-20023 MEDIUM KEV
SonicWall Email Security < 10.0.9.6173 - Authenticated Arbitrary File Read via Path Traversal
Apr 20, 2021
CVSS 4.9
EPSS 0.55
CVE-2021-20020 CRITICAL
SonicWall GMS 9.3 - Unauthenticated Command Execution
Apr 10, 2021
CVSS 9.8
EPSS 0.02
CVE-2021-20022 HIGH KEV
SonicWall Email Security < 10.0.9.6103 - Authenticated Arbitrary File Upload
Apr 09, 2021
CVSS 7.2
EPSS 0.33
CVE-2021-20021 CRITICAL KEVNUCLEI
SonicWall Email Security < 10.0.9.6103 - Unauthenticated Administrative Account Creation via Crafted HTTP Request
Apr 09, 2021
CVSS 9.8
EPSS 0.91
CVE-2021-3450 HIGH
OpenSSL 1.1.1h-1.1.1j - Certificate Chain Validation Bypass via X509_V_FLAG_X509_STRICT
Mar 25, 2021
CVSS 7.4
EPSS 0.01
CVE-2021-3449 MEDIUM
Openssl < 1.1.1k - NULL Pointer Dereference
Mar 25, 2021
CVSS 5.9
EPSS 0.10
CVE-2021-20018 MEDIUM
SonicWall SMA100 < 10.2.0.5 - Authenticated Configuration Export to Arbitrary Email
Mar 13, 2021
CVSS 4.9
EPSS 0.00
CVE-2021-20017 HIGH
SonicWall SMA100 < 10.2.0.5 - Authenticated OS Command Injection
Mar 13, 2021
CVSS 8.8
EPSS 0.03
CVE-2021-20016 CRITICAL KEV
SonicWall SMA100 Firmware 10.0.0.0-10.2.0.5-d-29sv - Unauthenticated SQL Injection
Feb 04, 2021
CVSS 9.8
EPSS 0.80
CVE-2020-5148 HIGH
SonicWall Directory Services Connector < 4.1.19 - Unauthenticated Password Hash Capture
Mar 05, 2021
CVSS 8.2
EPSS 0.00
CVE-2020-5147 MEDIUM
SonicWall NetExtender <10.2.300 - Privilege Escalation
Jan 09, 2021
CVSS 5.3
EPSS 0.00
CVE-2020-5146 HIGH
SonicWall SMA100 Firmware < 10.2.0.2-20sv - Authenticated OS Command Injection via HTTP POST Parameters
Jan 09, 2021
CVSS 7.2
EPSS 0.02
CVE-2020-5145 HIGH
SonicWall Global VPN Client < 4.10.4.0314 - Remote Code Execution via DLL Hijacking
Oct 28, 2020
CVSS 8.6
EPSS 0.00
CVE-2020-5144 HIGH
SonicWall Global VPN Client < 4.10.4.0314 - Privilege Escalation via Process Hijacking
Oct 28, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-5143 MEDIUM
SonicOS - Unauthenticated Administrator Username Enumeration via SSLVPN Login Page
Oct 12, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-5142 MEDIUM
SonicOS < 5.9.1.13, < 6.5.4.4 - Unauthenticated Stored Cross-Site Scripting in SSLVPN Web Interface
Oct 12, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-5141 MEDIUM
SonicOS < 5.9.1.13, < 6.5.4.4 - Unauthenticated Brute Force via Virtual Assist Ticket ID
Oct 12, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-5140 HIGH
SonicOS < 5.9.1.13 and < 6.5.4.4 - Unauthenticated Denial of Service via Malicious HTTP Request
Oct 12, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-5139 HIGH
SonicOS < 5.9.1.13 and < 6.5.4.4 - Unauthenticated Denial of Service via SSLVPN Invalid Pointer Release
Oct 12, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-5138 HIGH
SonicOS < 5.9.1.13 and < 6.5.4.4 - Unauthenticated Denial of Service via SSLVPN Heap Overflow
Oct 12, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-5137 HIGH
SonicOS < 5.9.1.13 and 6.5.4.4 - Unauthenticated Denial of Service via SSLVPN Buffer Overflow
Oct 12, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-5136 MEDIUM
SonicOS < 5.9.1.13, < 6.5.4.4 - Authenticated Denial of Service via SSL-VPN Buffer Overflow
Oct 12, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-5135 CRITICAL KEV
SonicOS < 6.0.5.3 and SonicOSv < 6.5.4.4 - Remote Code Execution via Malicious Request
Oct 12, 2020
CVSS 9.8
EPSS 0.24