« Volver al listado

CVE-2026-3469

Estado: AnalizadaBaja (2.7)—

A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-3469",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-3469",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-31T20:34:36.717764Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@sonicwall.com",
      "affectedData": [
        {
          "vendor": "SonicWall",
          "product": "Email Security",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.34.8215 and earlier versions"
            },
            {
              "status": "affected",
              "version": "10.0.34.8223 and earlier versions"
            }
          ],
          "platforms": [
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-03-31T21:16:33.163",
  "references": [
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@sonicwall.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@sonicwall.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de denegación de servicio (DoS) debido a una validación de entrada incorrecta en el dispositivo SonicWall Email Security, lo que permite a un atacante remoto autenticado como usuario administrador hacer que la aplicación deje de responder."
    }
  ],
  "lastModified": "2026-07-24T20:10:00.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD63C704-413C-43B7-9475-A19411E3BF6B",
              "versionEndExcluding": "10.0.35.8405"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sonicwall:esa5000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "91ED89A0-CFFB-44D3-8DE8-64E8DB635872"
            },
            {
              "criteria": "cpe:2.3:h:sonicwall:esa5050:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "69CD3296-0424-46C7-82F1-3BE7892B72C2"
            },
            {
              "criteria": "cpe:2.3:h:sonicwall:esa7000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3FE6D8AA-F614-404A-9006-A94763AA23B5"
            },
            {
              "criteria": "cpe:2.3:h:sonicwall:esa7050:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F748C59C-740B-4F52-9E0D-70F7D4E9AA07"
            },
            {
              "criteria": "cpe:2.3:h:sonicwall:esa9000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7D46ECFF-FA41-4861-A047-1EEFD89D13DD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "PSIRT@sonicwall.com"
}