Vulnerabilities > Sonicwall > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-13 CVE-2021-20025 Use of Hard-coded Credentials vulnerability in Sonicwall Email Security Virtual Appliance
SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup.
local
low complexity
sonicwall CWE-798
7.8
2021-04-09 CVE-2021-20022 Unrestricted Upload of File with Dangerous Type vulnerability in Sonicwall Email Security and Hosted Email Security
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
network
low complexity
sonicwall CWE-434
7.2
2021-03-25 CVE-2021-3450 Improper Certificate Validation vulnerability in multiple products
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain.
7.4
2021-03-13 CVE-2021-20017 OS Command Injection vulnerability in Sonicwall Sma100 Firmware 10.2.0.0/10.2.0.220Sv/10.2.0.5
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user.
network
low complexity
sonicwall CWE-78
8.8
2021-03-05 CVE-2020-5148 Improper Authentication vulnerability in Sonicwall Directory Services Connector
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.
network
low complexity
sonicwall CWE-287
8.2
2021-01-09 CVE-2020-5146 OS Command Injection vulnerability in Sonicwall SMA 100 Firmware
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters.
network
low complexity
sonicwall CWE-78
7.2
2020-10-28 CVE-2020-5145 Uncontrolled Search Path Element vulnerability in Sonicwall Global VPN Client 4.10.4.0314
SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability.
local
low complexity
sonicwall CWE-427
8.6
2020-10-28 CVE-2020-5144 Untrusted Search Path vulnerability in Sonicwall Global VPN Client 4.10.4.0314
SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.
local
low complexity
sonicwall CWE-426
7.8
2020-10-12 CVE-2020-5140 Out-of-bounds Read vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads to memory addresses leak.
network
low complexity
sonicwall CWE-125
7.5
2020-10-12 CVE-2020-5139 Release of Invalid Pointer or Reference vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall crash.
network
low complexity
sonicwall CWE-763
7.5