Skip to main content

Vendor/product archive

sonicwall / sonicos CVEs

Beta · best-effort

66 CVEs tagged to sonicwall / sonicos12 Critical, 25 High, 29 Medium, 0 Low, 0 Unrated.

CVE-2021-20019

Published Jun 23, 2021

A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosur…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-5143

Published Oct 12, 2020

SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerabil…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5142

Published Oct 12, 2020

A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5140

Published Oct 12, 2020

A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5139

Published Oct 12, 2020

A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5137

Published Oct 12, 2020

A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to firewall crash. Th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5136

Published Oct 12, 2020

A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assist portal, which leads to a firewall cr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5135

Published Oct 12, 2020

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the f…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
61.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-5134

Published Oct 12, 2020

A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a firewall crash. This vulnerability affected SonicOS Gen 6 versi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5133

Published Oct 12, 2020

A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall crash. This vulnerability affected…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5130

Published Jul 17, 2020

SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 66 CVEsPage 2 of 3