Show filters
208 Total Results
Displaying 41-50 of 208
Sort by:
Attacker Value
Unknown

CVE-2024-22395

Disclosure Date: February 24, 2024 (last updated December 21, 2024)
Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
Attacker Value
Unknown

CVE-2024-22394

Disclosure Date: February 08, 2024 (last updated February 15, 2024)
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.
Attacker Value
Unknown

CVE-2023-6340

Disclosure Date: January 18, 2024 (last updated January 30, 2024)
SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.
Attacker Value
Unknown

CVE-2023-5970

Disclosure Date: December 05, 2023 (last updated December 14, 2023)
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
Attacker Value
Unknown

CVE-2023-44221

Disclosure Date: December 05, 2023 (last updated December 14, 2023)
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Attacker Value
Unknown

CVE-2023-44220

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.
Attacker Value
Unknown

CVE-2023-44219

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.
Attacker Value
Unknown

CVE-2023-41715

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
Attacker Value
Unknown

CVE-2023-41713

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
Attacker Value
Unknown

CVE-2023-41712

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.