Vulnerabilities > Sonicwall > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-04-10 CVE-2021-20020 Improper Authentication vulnerability in Sonicwall Global Management System 9.3
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
network
low complexity
sonicwall CWE-287
critical
9.8
2021-04-09 CVE-2021-20021 Improper Privilege Management vulnerability in Sonicwall Email Security and Hosted Email Security
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
network
low complexity
sonicwall CWE-269
critical
9.8
2021-02-04 CVE-2021-20016 SQL Injection vulnerability in Sonicwall products
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.
network
low complexity
sonicwall CWE-89
critical
9.8
2020-10-12 CVE-2020-5135 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sonicwall Sonicos and Sonicosv
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
network
low complexity
sonicwall CWE-119
critical
9.8
2020-02-11 CVE-2013-1359 Improper Authentication vulnerability in Sonicwall products
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.
network
low complexity
sonicwall CWE-287
critical
9.8
2020-02-11 CVE-2013-1360 Improper Authentication vulnerability in Sonicwall products
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
network
low complexity
sonicwall CWE-287
critical
9.8
2019-12-31 CVE-2019-7478 SQL Injection vulnerability in Sonicwall Global Management System
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module.
network
low complexity
sonicwall CWE-89
critical
9.8
2019-12-23 CVE-2019-7489 Unspecified vulnerability in Sonicwall Email Security Appliance 10.0.2/7.4.5/7.5
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.
network
low complexity
sonicwall
critical
9.8
2019-12-23 CVE-2019-7488 Weak Password Requirements vulnerability in Sonicwall Email Security Appliance 10.0.2/7.4.5/7.5
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database.
network
low complexity
sonicwall CWE-521
critical
9.8
2019-12-19 CVE-2019-7482 Out-of-bounds Write vulnerability in Sonicwall SMA 100 Firmware 9.0.0.0/9.0.0.3
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so.
network
low complexity
sonicwall CWE-787
critical
9.8