Where
AND
AND
-Infinity
0

Vendor Risk Score

See how sonicwall compares to other vendors in security performance

View Risk Score →

Software

sonicwall sma 100
2
sonicwall sma 100 firmware
2
sonicwall sma100
2
sonicwall sma1000 appliances
2
sonicwall sma6210
2
sonicwall sma6210 firmware
2
sonicwall sma7210
2
sonicwall sma7210 firmware
2
sonicwall sma8200v
2
sonicwall email security
1
sonicwall email security appliance 3300
1
sonicwall email security appliance 3300 firmware
1
sonicwall email security appliance 4300
1
sonicwall email security appliance 4300 firmware
1
sonicwall email security appliance 5000
1
sonicwall email security appliance 5000 firmware
1
sonicwall email security appliance 5050
1
sonicwall email security appliance 5050 firmware
1
sonicwall email security appliance 7000
1
sonicwall email security appliance 7000 firmware
1
sonicwall email security appliance 7050
1
sonicwall email security appliance 7050 firmware
1
sonicwall email security appliance 8300
1
sonicwall email security appliance 8300 firmware
1
sonicwall email security appliance 9000
1
sonicwall email security appliance 9000 firmware
1
sonicwall email security virtual appliance
1
sonicwall hosted email security
1
sonicwall sma 200
1
sonicwall sma 200 firmware
1
sonicwall sma 210
1
sonicwall sma 210 firmware
1
sonicwall sma 400
1
sonicwall sma 400 firmware
1
sonicwall sma 410
1
sonicwall sma 410 firmware
1
sonicwall sma 500v
1
sonicwall sma 500v firmware
1
sonicwall sma 6200
1
sonicwall sma 6200 firmware
1
sonicwall sma 6210
1
sonicwall sma 6210 firmware
1
sonicwall sma 7200
1
sonicwall sma 7200 firmware
1
sonicwall sma 7210
1
sonicwall sma 7210 firmware
1
sonicwall sma 8200v
1
sonicwall sma 8200v firmware
1
sonicwall sma100 appliances
1
sonicwall sma1000
1
Severity
7.8
Command Injection, OS Command Injection
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

1 / 2
Source: MITRE
First published (updated )
Severity
7.2
3 Months
Code Injection
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

1 / 2
Source: MITRE
First published (updated )
Severity
8.1
EPSS
71.47%
Race Condition, Input Validation, Integer Overflow, Buffer Overflow
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

1 / 36
Source: MITRE
First published (updated )
Severity
7.2
Command Injection, OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

1 / 2
Source: MITRE
First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copypagetoiterpipe and pushpipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

1 / 4
First published (updated )
Severity
7.5
Malicious File Upload
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

1 / 2
First published (updated )
Severity
7.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

First published (updated )
Severity
7.5
SQL Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

1 / 2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203