Vulnerabilidades em SonicWall

190 resultados
Análise Vexday

O portfólio de vulnerabilidades da SonicWall apresenta uma taxa de exploração ativa significativamente elevada: 8,02% das CVEs catalogadas constam no CISA KEV, o que representa 17,8 vezes a média geral do catálogo — um indicador claro de que os produtos dessa fabricante são alvos recorrentes e prioritários para atores maliciosos. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), categoria que historicamente viabiliza execução remota de código com alto impacto. A CVE mais crítica em exploração ativa é CVE-2021-20038, com EPSS de 0,9991 — valor que sinaliza probabilidade extremamente alta de exploração observada ou iminente —, devendo ser tratada com prioridade máxima em qualquer plano de remediação. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com 8 provas de conceito públicas disponíveis, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo de ativos SonicWall expostos.

CVE-2019-7481HIGHVulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted EPSS 99.9%KEVCVE-2021-20038CRITICALA Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticEPSS 99.9%KEVCVE-2024-53704HIGHAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.EPSS 95.1%KEVCVE-2023-34127HIGHImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall AnalytiEPSS 86.5%CVE-2021-20021CRITICALA vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a craftedEPSS 83.4%KEVCVE-2021-20034An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete aEPSS 80.7%CVE-2026-15409CRITICALA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticatEPSS 78.4%KEVCVE-2021-20039HIGHImproper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authentiEPSS 78.1%CVE-2026-15410HIGHPost-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance ManEPSS 76.3%KEVCVE-2023-44221HIGHImproper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrEPSS 74.9%KEVCVE-2023-34133HIGHImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an EPSS 72.8%CVE-2023-0126HIGHPre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitEPSS 72.7%CVE-2022-22274A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of ServEPSS 57.3%CVE-2025-40598MEDIUMA Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker tEPSS 53.2%CVE-2025-40596HIGHA Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of SeEPSS 52.3%CVE-2021-20023MEDIUMSonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on thEPSS 50.2%KEVCVE-2023-34124CRITICALThe authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issueEPSS 46.4%CVE-2023-0656A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which EPSS 41.3%CVE-2023-34129Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenEPSS 41.2%CVE-2021-20044A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS systemEPSS 40.1%