Show filters
71 Total Results
Displaying 11-20 of 71
Sort by:
Attacker Value
Unknown
CVE-2024-53706
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
0
Attacker Value
Unknown
CVE-2024-53705
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
0
Attacker Value
Unknown
CVE-2024-40762
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
0
Attacker Value
Unknown
CVE-2024-40764
Disclosure Date: July 18, 2024 (last updated September 11, 2024)
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).
0
Attacker Value
Unknown
CVE-2024-3596
Disclosure Date: July 09, 2024 (last updated January 07, 2025)
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
0
Attacker Value
Unknown
CVE-2024-29013
Disclosure Date: June 20, 2024 (last updated August 20, 2024)
Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
0
Attacker Value
Unknown
CVE-2024-29012
Disclosure Date: June 20, 2024 (last updated August 20, 2024)
Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.
0
Attacker Value
Unknown
CVE-2024-22397
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.
0
Attacker Value
Unknown
CVE-2024-22396
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
0
Attacker Value
Unknown
CVE-2024-22394
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.
This issue affects only firmware version SonicOS 7.1.1-7040.
0