Vulnerabilidades em SonicWall

206 resultados
Análise Vexday

O portfólio de vulnerabilidades da SonicWall apresenta uma taxa de exploração ativa significativamente elevada: 8,02% das CVEs catalogadas constam no CISA KEV, o que representa 17,8 vezes a média geral do catálogo — um indicador claro de que os produtos dessa fabricante são alvos recorrentes e prioritários para atores maliciosos. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), categoria que historicamente viabiliza execução remota de código com alto impacto. A CVE mais crítica em exploração ativa é CVE-2021-20038, com EPSS de 0,9991 — valor que sinaliza probabilidade extremamente alta de exploração observada ou iminente —, devendo ser tratada com prioridade máxima em qualquer plano de remediação. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com 8 provas de conceito públicas disponíveis, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo de ativos SonicWall expostos.

CVE-2021-20046A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of SEPSS 1.9%CVE-2022-22273Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) pEPSS 1.9%CVE-2019-7488Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. TEPSS 1.9%CVE-2020-5146A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parametEPSS 1.9%CVE-2024-29014HIGHVulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary cEPSS 1.9%CVE-2021-20017A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobodEPSS 1.8%CVE-2020-5138A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPEPSS 1.8%CVE-2020-5139A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of InEPSS 1.8%CVE-2020-5140A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sendiEPSS 1.8%CVE-2020-5133A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a fireEPSS 1.8%CVE-2020-5137A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN EPSS 1.8%CVE-2020-5147SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privilEPSS 1.7%CVE-2020-5143SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based oEPSS 1.6%CVE-2019-7486Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacEPSS 1.6%CVE-2023-34135Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlyiEPSS 1.6%CVE-2026-78327CRITICALAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network SecuritEPSS 1.6%CVE-2019-7485Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impEPSS 1.5%CVE-2021-20019A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead EPSS 1.4%CVE-2019-7475A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to accessEPSS 1.4%CVE-2019-7476A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. ThiEPSS 1.4%