Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonicwall sma100 firmware vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2020-5132
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an atta...
Sonicwall Sma100 Firmware 10.2.0.2-20sv
Sonicwall Sma100 Firmware 12.4.0-2223
Sonicwall Sonicos 6.5.4.6-79n
8.8
CVSSv3
CVE-2021-20017
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated malicious user to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and previous versions.
Sonicwall Sma100 Firmware
4.9
CVSSv3
CVE-2021-20018
A post-authenticated vulnerability in SonicWall SMA100 allows an malicious user to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and previous versions.
Sonicwall Sma100 Firmware
7.5
CVSSv3
CVE-2021-20049
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated malicious user to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and previous versions 10.x versions.
Sonicwall Sma 100 Firmware
Sonicwall Sma 100 Firmware 10.2.0.8-37sv
Sonicwall Sma 100 Firmware 10.2.1.2-24sv
Sonicwall Sma 200 Firmware
Sonicwall Sma 200 Firmware 10.2.0.8-37sv
Sonicwall Sma 200 Firmware 10.2.1.2-24sv
Sonicwall Sma 210 Firmware
Sonicwall Sma 210 Firmware 10.2.0.8-37sv
Sonicwall Sma 210 Firmware 10.2.1.2-24sv
Sonicwall Sma 400 Firmware
Sonicwall Sma 400 Firmware 10.2.0.8-37sv
Sonicwall Sma 400 Firmware 10.2.1.2-24sv
Sonicwall Sma 410 Firmware
Sonicwall Sma 410 Firmware 10.2.0.8-37sv
Sonicwall Sma 410 Firmware 10.2.1.2-24sv
Sonicwall Sma 500v Firmware
Sonicwall Sma 500v Firmware 10.2.0.8-37sv
Sonicwall Sma 500v Firmware 10.2.1.2-24sv
9.8
CVSSv3
CVE-2021-20016
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated malicious user to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
Sonicwall Sma 100 Firmware
Sonicwall Sma 200 Firmware -
Sonicwall Sma 210 Firmware -
Sonicwall Sma 400 Firmware -
Sonicwall Sma 410 Firmware -
Sonicwall Sma 500v -
2 Articles
9.1
CVSSv3
CVE-2021-20034
An improper access control vulnerability in SMA100 allows a remote unauthenticated malicious user to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v
7.5
CVSSv3
CVE-2021-20050
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
Sonicwall Sma 100 Firmware
Sonicwall Sma 100 Firmware 10.2.0.8-37sv
Sonicwall Sma 100 Firmware 10.2.1.2-24sv
Sonicwall Sma 200 Firmware
Sonicwall Sma 200 Firmware 10.2.0.8-37sv
Sonicwall Sma 200 Firmware 10.2.1.2-24sv
Sonicwall Sma 210 Firmware
Sonicwall Sma 210 Firmware 10.2.0.8-37sv
Sonicwall Sma 210 Firmware 10.2.1.2-24sv
Sonicwall Sma 400 Firmware
Sonicwall Sma 400 Firmware 10.2.0.8-37sv
Sonicwall Sma 400 Firmware 10.2.1.2-24sv
Sonicwall Sma 410 Firmware
Sonicwall Sma 410 Firmware 10.2.0.8-37sv
Sonicwall Sma 410 Firmware 10.2.1.2-24sv
Sonicwall Sma 500v Firmware
Sonicwall Sma 500v Firmware 10.2.0.8-37sv
Sonicwall Sma 500v Firmware 10.2.1.2-24sv
1 Github repository
8.8
CVSSv3
CVE-2023-5970
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated malicious user to create an identical external domain user using accent characters, resulting in an MFA bypass.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
6.5
CVSSv3
CVE-2021-20035
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated malicious user to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v
7.2
CVSSv3
CVE-2023-44221
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »