Show filters
208 Total Results
Displaying 51-60 of 208
Sort by:
Attacker Value
Unknown

CVE-2023-41711

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash.
Attacker Value
Unknown

CVE-2023-39280

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.
Attacker Value
Unknown

CVE-2023-39279

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.
Attacker Value
Unknown

CVE-2023-39278

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.
Attacker Value
Unknown

CVE-2023-39277

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.
Attacker Value
Unknown

CVE-2023-39276

Disclosure Date: October 17, 2023 (last updated October 20, 2023)
SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
Attacker Value
Unknown

CVE-2023-44218

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.
Attacker Value
Unknown

CVE-2023-44217

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality.
Attacker Value
Unknown

CVE-2023-34137

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Attacker Value
Unknown

CVE-2023-34136

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.