Vulnerabilities > Sonicwall

DATE CVE VULNERABILITY TITLE RISK
2016-02-17 CVE-2016-2397 Command Injection vulnerability in Sonicwall products
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.
network
low complexity
sonicwall CWE-77
critical
10.0
2016-02-17 CVE-2016-2396 Command Injection vulnerability in Sonicwall products
The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to configuration input.
network
low complexity
sonicwall CWE-77
critical
9.9
2015-08-26 CVE-2015-4173 Unquoted Search Path or Element vulnerability in Sonicwall Netextender
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
6.9
2015-05-01 CVE-2015-2248 Cross-Site Request Forgery (CSRF) vulnerability in Sonicwall Remote Access Firmware
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.
network
sonicwall CWE-352
6.8
2015-04-29 CVE-2015-3447 Cross-site Scripting vulnerability in Sonicwall Sonicos 6.2.2.0/7.5.0.12
Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.
network
sonicwall CWE-79
4.3
2014-11-25 CVE-2014-8420 Improper Input Validation vulnerability in Sonicwall Analyzer, Global Management System and UMA Em5000
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors.
network
low complexity
sonicwall CWE-20
critical
9.0
2014-07-24 CVE-2014-5024 Cross-Site Scripting vulnerability in Sonicwall Analyzer, Global Management System and UMA Em5000
Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter.
network
sonicwall CWE-79
4.3
2014-07-16 CVE-2014-4977 SQL Injection vulnerability in Sonicwall Scrutinizer 11.0.1
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in the methodDetail function, or (4) xcNetworkDetail parameter in the xcNetworkDetail function in d4d/exporters.php.
network
low complexity
sonicwall CWE-89
6.5
2014-07-16 CVE-2014-4976 Permissions, Privileges, and Access Controls vulnerability in Sonicwall Scrutinizer 11.0.1
Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.
network
low complexity
sonicwall CWE-264
5.5
2014-04-17 CVE-2014-2879 Cross-Site Scripting vulnerability in Sonicwall Email Security Appliance
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.
network
sonicwall CWE-79
4.3