Skip to main content

Vendor/product archive

sonicwall / sma_210 CVEs

Beta · best-effort

33 CVEs tagged to sonicwall / sma_2109 Critical, 17 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-32821

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the…

CVSS 7.2 · High
evidence mentions
3
Buzz score
21.9

CVE-2025-32820

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writab…

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2025-32819

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting…

CVSS 8.8 · High
evidence mentions
8
Buzz score
30.0

CVE-2024-53703

Published Dec 5, 2024

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Sta…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-53702

Published Dec 5, 2024

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-45319

Published Dec 5, 2024

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement dur…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-45318

Published Dec 5, 2024

A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-40763

Published Dec 5, 2024

Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow an…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-38475

Published Jul 1, 2024

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the s…

CVSS 9.1 · Critical
evidence mentions
15
Buzz score
67.2
KEV listed

CVE-2024-22395

Published Feb 24, 2024

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated…

CVSS 6.3 · Medium

CVE-2023-5970

Published Dec 5, 2023

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, res…

CVSS 8.8 · High

CVE-2023-44221

Published Dec 5, 2023

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary com…

CVSS 7.2 · High
evidence mentions
6
Buzz score
57.5
KEV listed

CVE-2022-2915

Published Aug 26, 2022

A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentiall…

CVSS 8.8 · High

CVE-2022-22279

Published Apr 13, 2022

A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 ser…

CVSS 4.9 · Medium

CVE-2021-20045

Published Dec 8, 2021

A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1

CVE-2021-20044

Published Dec 8, 2021

A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulner…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2021-20043

Published Dec 8, 2021

A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the app…

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2021-20042

Published Dec 8, 2021

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 40…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Showing 1-25 of 33 CVEsPage 1 of 2