Vulnerabilities > Sonicwall > Sonicos

DATE CVE VULNERABILITY TITLE RISK
2024-08-23 CVE-2024-40766 Unspecified vulnerability in Sonicwall Sonicos
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash.
network
low complexity
sonicwall
critical
9.8
2024-07-18 CVE-2024-40764 Out-of-bounds Write vulnerability in Sonicwall Sonicos
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).
network
low complexity
sonicwall CWE-787
7.5
2024-06-20 CVE-2024-29012 Out-of-bounds Write vulnerability in Sonicwall Sonicos
Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.
network
low complexity
sonicwall CWE-787
7.5
2024-06-20 CVE-2024-29013 Out-of-bounds Write vulnerability in Sonicwall Sonicos
Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
network
low complexity
sonicwall CWE-787
6.5
2024-02-08 CVE-2024-22394 Improper Authentication vulnerability in Sonicwall Sonicos 7.1.17040
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.
network
low complexity
sonicwall CWE-287
critical
9.8
2023-10-17 CVE-2023-39276 Out-of-bounds Write vulnerability in Sonicwall Sonicos
SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
network
low complexity
sonicwall CWE-787
6.5
2023-10-17 CVE-2023-39277 Out-of-bounds Write vulnerability in Sonicwall Sonicos
SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.
network
low complexity
sonicwall CWE-787
6.5
2023-10-17 CVE-2023-39278 Out-of-bounds Write vulnerability in Sonicwall Sonicos
SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.
network
low complexity
sonicwall CWE-787
6.5
2023-10-17 CVE-2023-39279 Out-of-bounds Write vulnerability in Sonicwall Sonicos
SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.
network
low complexity
sonicwall CWE-787
6.5
2023-10-17 CVE-2023-39280 Out-of-bounds Write vulnerability in Sonicwall Sonicos
SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.
network
low complexity
sonicwall CWE-787
6.5