Skip to main content

Vendor/product archive

sonicwall / sma_500v_firmware CVEs

Beta · best-effort

32 CVEs tagged to sonicwall / sma_500v_firmware7 Critical, 19 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-32821

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the…

CVSS 7.2 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-32820

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writab…

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-32819

Published May 7, 2025

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting…

CVSS 8.8 · High
evidence mentions
10
Buzz score
42.0

CVE-2024-53703

Published Dec 5, 2024

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Sta…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-53702

Published Dec 5, 2024

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-45319

Published Dec 5, 2024

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement dur…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-45318

Published Dec 5, 2024

A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-40763

Published Dec 5, 2024

Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow an…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-38475

Published Jul 1, 2024

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the s…

CVSS 9.1 · Critical
evidence mentions
15
Buzz score
67.2
KEV listed

CVE-2024-22395

Published Feb 24, 2024

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated…

CVSS 6.3 · Medium

CVE-2023-5970

Published Dec 5, 2023

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, res…

CVSS 8.8 · High

CVE-2023-44221

Published Dec 5, 2023

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary com…

CVSS 7.2 · High
evidence mentions
6
Buzz score
57.5
KEV listed

CVE-2022-2915

Published Aug 26, 2022

A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentiall…

CVSS 8.8 · High

CVE-2022-22279

Published Apr 13, 2022

A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 ser…

CVSS 4.9 · Medium

CVE-2021-20050

Published Dec 23, 2021

An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuratio…

CVSS 7.5 · High

CVE-2021-20049

Published Dec 23, 2021

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnera…

CVSS 7.5 · High

CVE-2021-20045

Published Dec 8, 2021

A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1

CVE-2021-20044

Published Dec 8, 2021

A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulner…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Showing 1-25 of 32 CVEsPage 1 of 2