Vulnerabilities > Sonicwall > Sonicos > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-14 CVE-2021-20027 Classic Buffer Overflow vulnerability in Sonicwall Sonicos
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request.
network
low complexity
sonicwall CWE-120
7.5
2021-03-25 CVE-2021-3450 Improper Certificate Validation vulnerability in multiple products
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain.
7.4
2020-10-12 CVE-2020-5140 Out-of-bounds Read vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads to memory addresses leak.
network
low complexity
sonicwall CWE-125
7.5
2020-10-12 CVE-2020-5139 Release of Invalid Pointer or Reference vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall crash.
network
low complexity
sonicwall CWE-763
7.5
2020-10-12 CVE-2020-5138 Out-of-bounds Write vulnerability in Sonicwall Sonicos and Sonicosv
A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash.
network
low complexity
sonicwall CWE-787
7.5
2020-10-12 CVE-2020-5137 Classic Buffer Overflow vulnerability in Sonicwall Sonicos and Sonicosv
A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to firewall crash.
network
low complexity
sonicwall CWE-120
7.5
2020-10-12 CVE-2020-5133 Classic Buffer Overflow vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall crash.
network
low complexity
sonicwall CWE-120
7.5
2019-12-31 CVE-2019-7479 Improper Privilege Management vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode.
network
low complexity
sonicwall CWE-269
7.2
2019-12-19 CVE-2019-7487 Unquoted Search Path or Element vulnerability in Sonicwall Sonicos
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
local
low complexity
sonicwall CWE-428
7.8
2019-08-09 CVE-2019-12258 Session Fixation vulnerability in multiple products
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component.
network
low complexity
windriver sonicwall siemens netapp belden CWE-384
7.5