Sonicwall
Sonicwall SMA 410 Firmware: vulnerabilidades y CVE
Sonicwall SMA 410 Firmware tiene 35 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 9 son críticas y 6 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses1
Críticas9
Explotadas activamente6
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44221 | Alta (7.2) | 76% | ⚠ Explotación activa | 5 dic 2023 | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially… |
| CVE-2024-38475 | Crítica (9.1) | 100% | ⚠ Explotación activa | 1 jul 2024 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly… |
| CVE-2021-20035 | Media (6.5) | 4.2% | ⚠ Explotación activa | 27 sept 2021 | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS. |
| CVE-2021-20028 | Crítica (9.8) | 30% | ⚠ Explotación activa | 4 ago 2021 | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or… |
| CVE-2021-20038 | Crítica (9.8) | 100% | ⚠ Explotación activa | 8 dic 2021 | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance.… |
| CVE-2021-20016 | Crítica (9.8) | 40% | ⚠ Explotación activa | 4 feb 2021 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-40603 | Media (4.5) | 0.45% | — | 31 oct 2025 | A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data. |
| CVE-2025-40598 | Media (6.1) | 64% | — | 23 jul 2025 | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code. |
| CVE-2025-40597 | Alta (7.5) | 30% | — | 23 jul 2025 | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. |
| CVE-2025-40596 | Alta (7.3) | 56% | — | 23 jul 2025 | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. |
| CVE-2025-40599 | Crítica (9.1) | 14% | — | 23 jul 2025 | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system,… |
| CVE-2025-32821 | Alta (7.2) | 20% | — | 7 may 2025 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance. |
| CVE-2025-32820 | Alta (8.8) | 2.9% | — | 7 may 2025 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable. |
| CVE-2025-32819 | Alta (8.8) | 6.4% | — | 7 may 2025 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. |
| CVE-2024-53703 | Alta (8.1) | 13% | — | 5 dic 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially… |
| CVE-2024-53702 | Media (5.3) | 0.33% | — | 5 dic 2024 | Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the… |
| CVE-2024-45319 | Media (6.3) | 0.23% | — | 5 dic 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication. |
| CVE-2024-45318 | Alta (8.1) | 1.0% | — | 5 dic 2024 | A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution. |
| CVE-2024-40763 | Alta (7.5) | 0.94% | — | 5 dic 2024 | Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution. |
| CVE-2024-38475 | Crítica (9.1) | 100% | ⚠ Explotación activa | 1 jul 2024 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly… |
| CVE-2024-22395 | Media (6.3) | 0.43% | — | 24 feb 2024 | Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's… |
| CVE-2023-5970 | Alta (8.8) | 0.91% | — | 5 dic 2023 | Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass. |
| CVE-2023-44221 | Alta (7.2) | 76% | ⚠ Explotación activa | 5 dic 2023 | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially… |
| CVE-2022-2915 | Alta (8.8) | 6.7% | — | 26 ago 2022 | A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This… |
| CVE-2022-1703 | Alta (8.8) | 12% | — | 8 jun 2022 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution… |
| CVE-2022-22279 | Media (4.9) | 1.1% | — | 13 abr 2022 | A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA… |
| CVE-2022-22273 | Crítica (9.8) | 1.9% | — | 17 mar 2022 | Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series… |
| CVE-2021-20050 | Alta (7.5) | 0.90% | — | 23 dic 2021 | An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data. |
| CVE-2021-20049 | Alta (7.5) | 1.3% | — | 23 dic 2021 | A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv,… |
| CVE-2021-20045 | Crítica (9.8) | 25% | — | 8 dic 2021 | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability… |
| CVE-2021-20044 | Alta (8.8) | 40% | — | 8 dic 2021 | A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410… |
| CVE-2021-20043 | Alta (8.8) | 23% | — | 8 dic 2021 | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA… |
| CVE-2021-20042 | Crítica (9.8) | 2.6% | — | 8 dic 2021 | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. |
| CVE-2021-20041 | Alta (7.5) | 6.6% | — | 8 dic 2021 | An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This… |
| CVE-2021-20040 | Alta (7.5) | 25% | — | 8 dic 2021 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410… |
| CVE-2021-20039 | Alta (8.8) | 79% | — | 8 dic 2021 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This… |