Sonicwall
Sonicwall Sonicos: vulnerabilidades y CVE
Sonicwall Sonicos tiene 78 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 14 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE78
Últimos 12 meses10
Críticas14
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-53704 | Crítica (9.8) | 95% | ⚠ Explotación activa | 9 ene 2025 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. |
| CVE-2024-40766 | Crítica (9.8) | 18% | ⚠ Explotación activa | 23 ago 2024 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash.… |
| CVE-2020-5135 | Crítica (9.8) | 27% | ⚠ Explotación activa | 12 oct 2020 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-0516 | Media (6.5) | 0.34% | — | 5 ago 2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. |
| CVE-2026-0206 | Media (4.9) | 0.50% | — | 29 abr 2026 | A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0205 | Media (6.8) | 0.39% | — | 29 abr 2026 | A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. |
| CVE-2026-0204 | Alta (8) | 0.38% | — | 29 abr 2026 | A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. |
| CVE-2026-3439 | Media (4.9) | 0.39% | — | 4 mar 2026 | A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. |
| CVE-2026-0402 | Media (4.9) | 0.36% | — | 24 feb 2026 | A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0401 | Media (4.9) | 0.36% | — | 24 feb 2026 | A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0400 | Media (4.9) | 0.44% | — | 24 feb 2026 | A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0399 | Media (4.9) | 0.33% | — | 24 feb 2026 | Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. |
| CVE-2025-40601 | Alta (7.5) | 1.2% | — | 20 nov 2025 | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. |
| CVE-2025-40600 | Crítica (9.8) | 0.91% | — | 29 jul 2025 | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. |
| CVE-2025-32818 | Alta (7.5) | 0.83% | — | 23 abr 2025 | A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition. |
| CVE-2024-40765 | Crítica (9.8) | 0.80% | — | 9 ene 2025 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially… |
| CVE-2024-12806 | Media (4.9) | 0.64% | — | 9 ene 2025 | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file. |
| CVE-2024-12805 | Alta (7.2) | 0.71% | — | 9 ene 2025 | A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. |
| CVE-2024-12803 | Alta (7.2) | 0.80% | — | 9 ene 2025 | A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. |
| CVE-2024-53705 | Alta (7.5) | 0.74% | — | 9 ene 2025 | A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall. |
| CVE-2024-53704 | Crítica (9.8) | 95% | ⚠ Explotación activa | 9 ene 2025 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. |
| CVE-2024-40762 | Crítica (9.8) | 1.0% | — | 9 ene 2025 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication… |
| CVE-2024-40766 | Crítica (9.8) | 18% | ⚠ Explotación activa | 23 ago 2024 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash.… |
| CVE-2024-40764 | Alta (7.5) | 0.70% | — | 18 jul 2024 | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). |
| CVE-2024-3596 | Crítica (9) | 15% | — | 9 jul 2024 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix… |
| CVE-2024-29013 | Media (6.5) | 0.64% | — | 20 jun 2024 | Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function. |
| CVE-2024-29012 | Alta (7.5) | 0.54% | — | 20 jun 2024 | Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function. |
| CVE-2024-22397 | Alta (8.3) | 1.1% | — | 14 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary… |
| CVE-2024-22396 | Media (5.3) | 1.1% | — | 14 mar 2024 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially… |
| CVE-2024-22394 | Crítica (9.8) | 0.75% | — | 8 feb 2024 | An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware… |
| CVE-2023-41715 | Alta (8.8) | 0.65% | — | 17 oct 2023 | SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel. |
| CVE-2023-41713 | Alta (7.5) | 0.59% | — | 17 oct 2023 | SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. |
| CVE-2023-41712 | Media (6.5) | 0.80% | — | 17 oct 2023 | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.