Vulnerabilities > Sonicwall > Sonicos > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-18 CVE-2024-40764 Out-of-bounds Write vulnerability in Sonicwall Sonicos
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).
network
low complexity
sonicwall CWE-787
7.5
2024-06-20 CVE-2024-29012 Out-of-bounds Write vulnerability in Sonicwall Sonicos
Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.
network
low complexity
sonicwall CWE-787
7.5
2023-10-17 CVE-2023-41713 Use of Hard-coded Credentials vulnerability in Sonicwall Sonicos
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
network
low complexity
sonicwall CWE-798
7.5
2023-10-17 CVE-2023-41715 Improper Privilege Management vulnerability in Sonicwall Sonicos
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
network
low complexity
sonicwall CWE-269
8.8
2023-03-02 CVE-2023-0656 Out-of-bounds Write vulnerability in Sonicwall Sonicos
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
network
low complexity
sonicwall CWE-787
7.5
2023-03-02 CVE-2023-1101 Improper Restriction of Excessive Authentication Attempts vulnerability in Sonicwall Sonicos
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
network
low complexity
sonicwall CWE-307
8.8
2022-04-27 CVE-2022-22275 Unspecified vulnerability in Sonicwall Sonicos
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.
network
low complexity
sonicwall
7.5
2022-01-10 CVE-2021-20046 Out-of-bounds Write vulnerability in Sonicwall Sonicos
A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall.
network
low complexity
sonicwall CWE-787
8.8
2022-01-10 CVE-2021-20048 Out-of-bounds Write vulnerability in Sonicwall Sonicos
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall.
network
low complexity
sonicwall CWE-787
8.8
2021-06-23 CVE-2021-20019 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.
network
low complexity
sonicwall CWE-119
7.5