Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonicwall sma 500v - vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2022-1703
Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated malicious user to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.
Sonicwall Sma 210 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
9.8
CVSSv3
CVE-2021-20028
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
Sonicwall Sma 210 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
1 Article
9.1
CVSSv3
CVE-2021-20034
An improper access control vulnerability in SMA100 allows a remote unauthenticated malicious user to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v
6.5
CVSSv3
CVE-2021-20035
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated malicious user to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v
7.2
CVSSv3
CVE-2023-44221
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
8.8
CVSSv3
CVE-2023-5970
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated malicious user to create an identical external domain user using accent characters, resulting in an MFA bypass.
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
8.8
CVSSv3
CVE-2022-2915
A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated malicious user to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and previous versions versio...
Sonicwall Sma 200 Firmware
Sonicwall Sma 210 Firmware
Sonicwall Sma 400 Firmware
Sonicwall Sma 410 Firmware
Sonicwall Sma 500v Firmware
9.8
CVSSv3
CVE-2021-20016
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated malicious user to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
Sonicwall Sma 100 Firmware
Sonicwall Sma 200 Firmware -
Sonicwall Sma 210 Firmware -
Sonicwall Sma 400 Firmware -
Sonicwall Sma 410 Firmware -
Sonicwall Sma 500v -
2 Articles
7.5
CVSSv3
CVE-2021-20049
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated malicious user to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and previous versions 10.x versions.
Sonicwall Sma 100 Firmware
Sonicwall Sma 100 Firmware 10.2.0.8-37sv
Sonicwall Sma 100 Firmware 10.2.1.2-24sv
Sonicwall Sma 200 Firmware
Sonicwall Sma 200 Firmware 10.2.0.8-37sv
Sonicwall Sma 200 Firmware 10.2.1.2-24sv
Sonicwall Sma 210 Firmware
Sonicwall Sma 210 Firmware 10.2.0.8-37sv
Sonicwall Sma 210 Firmware 10.2.1.2-24sv
Sonicwall Sma 400 Firmware
Sonicwall Sma 400 Firmware 10.2.0.8-37sv
Sonicwall Sma 400 Firmware 10.2.1.2-24sv
Sonicwall Sma 410 Firmware
Sonicwall Sma 410 Firmware 10.2.0.8-37sv
Sonicwall Sma 410 Firmware 10.2.1.2-24sv
Sonicwall Sma 500v Firmware
Sonicwall Sma 500v Firmware 10.2.0.8-37sv
Sonicwall Sma 500v Firmware 10.2.1.2-24sv
7.5
CVSSv3
CVE-2021-20050
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
Sonicwall Sma 100 Firmware
Sonicwall Sma 100 Firmware 10.2.0.8-37sv
Sonicwall Sma 100 Firmware 10.2.1.2-24sv
Sonicwall Sma 200 Firmware
Sonicwall Sma 200 Firmware 10.2.0.8-37sv
Sonicwall Sma 200 Firmware 10.2.1.2-24sv
Sonicwall Sma 210 Firmware
Sonicwall Sma 210 Firmware 10.2.0.8-37sv
Sonicwall Sma 210 Firmware 10.2.1.2-24sv
Sonicwall Sma 400 Firmware
Sonicwall Sma 400 Firmware 10.2.0.8-37sv
Sonicwall Sma 400 Firmware 10.2.1.2-24sv
Sonicwall Sma 410 Firmware
Sonicwall Sma 410 Firmware 10.2.0.8-37sv
Sonicwall Sma 410 Firmware 10.2.1.2-24sv
Sonicwall Sma 500v Firmware
Sonicwall Sma 500v Firmware 10.2.0.8-37sv
Sonicwall Sma 500v Firmware 10.2.1.2-24sv
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »