Show filters
208 Total Results
Displaying 21-30 of 208
Sort by:
Attacker Value
Unknown

CVE-2024-40765

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
0
Attacker Value
Unknown

CVE-2024-12806

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
0
Attacker Value
Unknown

CVE-2024-12805

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
0
Attacker Value
Unknown

CVE-2024-12803

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
0
Attacker Value
Unknown

CVE-2024-53706

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
0
Attacker Value
Unknown

CVE-2024-53705

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
0
Attacker Value
Unknown

CVE-2024-40762

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
0
Attacker Value
Unknown

CVE-2024-45317

Disclosure Date: October 11, 2024 (last updated October 12, 2024)
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
0
Attacker Value
Unknown

CVE-2024-45316

Disclosure Date: October 11, 2024 (last updated October 12, 2024)
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege escalation attack.
0
Attacker Value
Unknown

CVE-2024-45315

Disclosure Date: October 11, 2024 (last updated October 12, 2024)
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack.
0