Show filters
208 Total Results
Displaying 21-30 of 208
Sort by:
Attacker Value
Unknown
CVE-2024-40765
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
0
Attacker Value
Unknown
CVE-2024-12806
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
0
Attacker Value
Unknown
CVE-2024-12805
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
0
Attacker Value
Unknown
CVE-2024-12803
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
0
Attacker Value
Unknown
CVE-2024-53706
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
0
Attacker Value
Unknown
CVE-2024-53705
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
0
Attacker Value
Unknown
CVE-2024-40762
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
0
Attacker Value
Unknown
CVE-2024-45317
Disclosure Date: October 11, 2024 (last updated October 12, 2024)
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
0
Attacker Value
Unknown
CVE-2024-45316
Disclosure Date: October 11, 2024 (last updated October 12, 2024)
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege escalation attack.
0
Attacker Value
Unknown
CVE-2024-45315
Disclosure Date: October 11, 2024 (last updated October 12, 2024)
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack.
0