Vulnerabilities in SonicWall

206 results
Vexday analysis

O portfólio de vulnerabilidades da SonicWall apresenta uma taxa de exploração ativa significativamente elevada: 8,02% das CVEs catalogadas constam no CISA KEV, o que representa 17,8 vezes a média geral do catálogo — um indicador claro de que os produtos dessa fabricante são alvos recorrentes e prioritários para atores maliciosos. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), categoria que historicamente viabiliza execução remota de código com alto impacto. A CVE mais crítica em exploração ativa é CVE-2021-20038, com EPSS de 0,9991 — valor que sinaliza probabilidade extremamente alta de exploração observada ou iminente —, devendo ser tratada com prioridade máxima em qualquer plano de remediação. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com 8 provas de conceito públicas disponíveis, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo de ativos SonicWall expostos.

CVE-2026-0516MEDIUMA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the HostEPSS 0.3%CVE-2026-18634HIGHAn insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and EPSS 0.3%CVE-2024-53706HIGHA vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges toEPSS 0.3%CVE-2025-2170HIGHA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific condEPSS 0.3%CVE-2026-0399MEDIUMMultiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checkingEPSS 0.3%CVE-2025-40605MEDIUMA Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injEPSS 0.3%CVE-2024-53702MEDIUMUse of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that,EPSS 0.3%CVE-2023-34130—SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects EPSS 0.3%CVE-2026-66146MEDIUMMultiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote EPSS 0.3%CVE-2023-44220—SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in thEPSS 0.3%CVE-2026-3468MEDIUMA stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralizatiEPSS 0.3%CVE-2024-45316HIGHThe Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlierEPSS 0.3%CVE-2026-66150HIGHImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated atEPSS 0.3%CVE-2026-66149HIGHImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated atEPSS 0.3%CVE-2026-66153HIGHThe NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to maniEPSS 0.2%CVE-2024-45315MEDIUMThe Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlierEPSS 0.2%CVE-2024-45319MEDIUMA vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can cirEPSS 0.2%CVE-2023-6340MEDIUMSonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. EPSS 0.2%CVE-2018-9867—In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in EPSS 0.2%CVE-2023-44218HIGH A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system EPSS 0.2%