cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-40766,https://securityvulnerability.io/vulnerability/CVE-2024-40766,Improper Access Control Vulnerability Affects Sonicwall Firewalls,"An improper access control issue has been detected in the management access of SonicWall's SonicOS. This vulnerability can allow unauthorized access to various resources within affected SonicWall Firewall devices, potentially leading to significant security risks. In certain scenarios, this vulnerability may also result in the firewall crashing, affecting the overall security posture and functionality of the network environment. The affected devices include generations 5, 6, and 7 of SonicWall Firewalls operating on SonicOS versions 7.0.1-5035 and earlier. Users are urged to review their systems and apply the necessary updates to mitigate associated risks.",Sonicwall,Sonicos,9.8,CRITICAL,0.008190000429749489,true,true,true,true,,true,true,2024-08-23T06:19:07.229Z,6143 CVE-2024-40764,https://securityvulnerability.io/vulnerability/CVE-2024-40764,Unauthenticated DoS Vulnerability in SonicOS IPSec VPN,"A heap-based buffer overflow vulnerability has been identified in the SonicOS IPSec VPN, which can be exploited by unauthenticated remote attackers. The exploitation of this vulnerability could lead to a Denial of Service (DoS), affecting the availability of the service. It is critical for users of this platform to apply the recommended security patches and updates as provided by SonicWall to protect against potential threats. For further details on mitigation strategies, refer to the vendor advisory.",Sonicwall,Sonicos,7.5,HIGH,0.0004600000102072954,false,false,false,false,,false,false,2024-07-18T07:42:37.995Z,0 CVE-2024-29013,https://securityvulnerability.io/vulnerability/CVE-2024-29013,SonicOS SSL-VPN Buffer Overflow Vulnerability Leads to Denial of Service,Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.,Sonicwall,Sonicos,6.5,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2024-06-20T08:14:23.845Z,0 CVE-2024-29012,https://securityvulnerability.io/vulnerability/CVE-2024-29012,SonicOS HTTP Server Buffer Overflow Vulnerability Leads to DoS,"The SonicOS HTTP server is susceptible to a stack-based buffer overflow vulnerability that can be exploited by an authenticated remote attacker. By leveraging this vulnerability, an attacker can utilize the sscanf function to manipulate buffer allocations, ultimately causing a Denial of Service (DoS) condition. This issue highlights the critical nature of secure coding practices and the importance of timely patch management to protect against potential attack vectors.",Sonicwall,Sonicos,7.5,HIGH,0.0004600000102072954,false,false,false,false,,false,false,2024-06-20T08:11:10.318Z,0 CVE-2024-22397,https://securityvulnerability.io/vulnerability/CVE-2024-22397,Arbitrary JavaScript Code Execution Vulnerability in SonicOS SSLVPN Portal,Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.,Sonicwall,Sonicos,,,0.0004299999854993075,false,false,false,false,,false,false,2024-03-14T03:23:52.971Z,0 CVE-2024-22396,https://securityvulnerability.io/vulnerability/CVE-2024-22396,Integer-based buffer overflow vulnerability allows DoS and arbitrary code execution,An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.,Sonicwall,Sonicos,,,0.0004299999854993075,false,false,false,false,,false,false,2024-03-14T03:15:55.008Z,0 CVE-2024-22394,https://securityvulnerability.io/vulnerability/CVE-2024-22394,Improper Authentication Vulnerability Affects SonicWall SSL-VPN,"An improper authentication vulnerability exists within the SSL-VPN feature of SonicWall's SonicOS. When exploited under specific conditions, this vulnerability enables a remote attacker to bypass the authentication mechanism, potentially leading to unauthorized access. This issue is present exclusively in SonicOS firmware version 7.1.1-7040, posing a significant risk to organizations using this version for secure remote access.",SonicWall,SonicOS,9.8,CRITICAL,0.000910000002477318,false,false,false,false,,false,false,2024-02-08T01:14:33.634Z,0 CVE-2023-41711,https://securityvulnerability.io/vulnerability/CVE-2023-41711,,"SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.",Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-41713,https://securityvulnerability.io/vulnerability/CVE-2023-41713,,SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.,Sonicwall,Sonicos,7.5,HIGH,0.0013500000350177288,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-41712,https://securityvulnerability.io/vulnerability/CVE-2023-41712,,SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.,Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-39280,https://securityvulnerability.io/vulnerability/CVE-2023-39280,,"SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash. ",Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-41715,https://securityvulnerability.io/vulnerability/CVE-2023-41715,,"SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel. ",SonicWall,SonicOS,8.8,HIGH,0.0008900000248104334,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-39278,https://securityvulnerability.io/vulnerability/CVE-2023-39278,,"SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash. ",Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-39279,https://securityvulnerability.io/vulnerability/CVE-2023-39279,,SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.,Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-39276,https://securityvulnerability.io/vulnerability/CVE-2023-39276,," SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. ",Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-39277,https://securityvulnerability.io/vulnerability/CVE-2023-39277,," SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.",Sonicwall,Sonicos,6.5,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-10-17T23:15:00.000Z,0 CVE-2023-0656,https://securityvulnerability.io/vulnerability/CVE-2023-0656,,"A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.",SonicWall,SonicOS,7.5,HIGH,0.002199999988079071,false,true,false,true,true,false,false,2023-03-02T00:00:00.000Z,0 CVE-2023-1101,https://securityvulnerability.io/vulnerability/CVE-2023-1101,,SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.,SonicWall,SonicOS,8.8,HIGH,0.0011399999493733048,false,false,false,false,,false,false,2023-03-02T00:00:00.000Z,0 CVE-2022-22278,https://securityvulnerability.io/vulnerability/CVE-2022-22278,,A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack,Sonicwall,Sonicos,7.5,HIGH,0.000910000002477318,false,false,false,false,,false,false,2022-04-27T16:25:18.000Z,0 CVE-2022-22277,https://securityvulnerability.io/vulnerability/CVE-2022-22277,,A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.,Sonicwall,Sonicos,5.3,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2022-04-27T16:25:16.000Z,0 CVE-2022-22276,https://securityvulnerability.io/vulnerability/CVE-2022-22276,,A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.,Sonicwall,Sonicos,5.3,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2022-04-27T16:25:15.000Z,0 CVE-2022-22275,https://securityvulnerability.io/vulnerability/CVE-2022-22275,,Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.,Sonicwall,Sonicos,7.5,HIGH,0.000910000002477318,false,false,false,false,,false,false,2022-04-27T16:25:13.000Z,0 CVE-2022-22274,https://securityvulnerability.io/vulnerability/CVE-2022-22274,SonicOS Buffer Overflow Vulnerability Allows Remote DoS or Code Execution,A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.,Sonicwall,Sonicos,9.8,CRITICAL,0.004999999888241291,false,false,false,true,true,false,false,2022-03-25T23:05:09.000Z,0 CVE-2021-20048,https://securityvulnerability.io/vulnerability/CVE-2021-20048,,"A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.",Sonicwall,Sonicos,8.8,HIGH,0.003160000080242753,false,false,false,false,,false,false,2022-01-10T14:10:00.000Z,0 CVE-2021-20046,https://securityvulnerability.io/vulnerability/CVE-2021-20046,,"A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.",Sonicwall,Sonicos,8.8,HIGH,0.003160000080242753,false,false,false,false,,false,false,2022-01-10T14:10:00.000Z,0