Vulnerabilidades em SonicWall

190 resultados
Análise Vexday

O portfólio de vulnerabilidades da SonicWall apresenta uma taxa de exploração ativa significativamente elevada: 8,02% das CVEs catalogadas constam no CISA KEV, o que representa 17,8 vezes a média geral do catálogo — um indicador claro de que os produtos dessa fabricante são alvos recorrentes e prioritários para atores maliciosos. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), categoria que historicamente viabiliza execução remota de código com alto impacto. A CVE mais crítica em exploração ativa é CVE-2021-20038, com EPSS de 0,9991 — valor que sinaliza probabilidade extremamente alta de exploração observada ou iminente —, devendo ser tratada com prioridade máxima em qualquer plano de remediação. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com 8 provas de conceito públicas disponíveis, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo de ativos SonicWall expostos.

CVE-2021-20016CRITICALA SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to accessEPSS 37.0%KEVCVE-2025-32821HIGHA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell comEPSS 32.4%CVE-2021-20028CRITICALImproper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, sEPSS 29.9%KEVCVE-2025-40597HIGHA Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of SerEPSS 27.6%CVE-2021-20040A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages orEPSS 25.8%CVE-2023-34125Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wiEPSS 25.4%CVE-2021-20045A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentialEPSS 25.2%CVE-2020-5135CRITICALA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code EPSS 24.6%KEVCVE-2025-23006CRITICALPre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) andEPSS 23.4%KEVCVE-2021-20043A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially exeEPSS 23.3%CVE-2024-40766CRITICALAn improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorizedEPSS 18.2%KEVCVE-2021-20022HIGHSonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to EPSS 16.5%KEVCVE-2021-20031A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary wEPSS 13.0%CVE-2024-53703HIGHA vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web servEPSS 12.7%CVE-2021-20026A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP rEPSS 11.6%CVE-2022-1703Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attackEPSS 11.6%CVE-2025-40599CRITICALAn authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrEPSS 10.4%CVE-2022-22280Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWaEPSS 9.4%CVE-2022-1702SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an exterEPSS 8.9%CVE-2019-7482Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulneraEPSS 8.8%