Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2025-23007

Disclosure Date: January 30, 2025 (last updated January 30, 2025)
A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.
0
Attacker Value
Unknown

CVE-2024-29014

Disclosure Date: July 18, 2024 (last updated September 11, 2024)
Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.
Attacker Value
Unknown

CVE-2023-6340

Disclosure Date: January 18, 2024 (last updated January 30, 2024)
SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.
Attacker Value
Unknown

CVE-2023-44220

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.
Attacker Value
Unknown

CVE-2023-44218

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.
Attacker Value
Unknown

CVE-2023-44217

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality.
Attacker Value
Unknown

CVE-2022-22281

Disclosure Date: May 13, 2022 (last updated October 07, 2023)
A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.
Attacker Value
Unknown

CVE-2020-5147

Disclosure Date: January 09, 2021 (last updated February 22, 2025)
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.
Attacker Value
Unknown

CVE-2020-5131

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier.
Attacker Value
Unknown

CVE-2015-4173

Disclosure Date: August 26, 2015 (last updated October 05, 2023)
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
0