Known vulnerabilities in SonicWall GMS

Vendor: SonicWall
Software: SonicWall GMS
Software CPE: cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*
Total vulnerabilities: 26
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SonicWall GMS SonicWall GMS is affected by 26 known vulnerabilities: 9 high, 13 medium, 4 low Critical High Medium Low

Vulnerabilities (26)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141445 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-66145
CWE-94 High
No
No
9.5.2 11.08.2026 SB2026081137
#VU141446 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-66146
CWE-79 Low
No
No
9.5.2 11.08.2026 SB2026081137
#VU141447 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-66147
CWE-94 High
No
No
9.5.2 11.08.2026 SB2026081137
#VU141448 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-66148
CWE-94 Low
No
No
9.5.2 11.08.2026 SB2026081137
#VU141449 - Improper Certificate Validation
CVE-2026-66154
CWE-295 Medium
No
No
9.5.2 11.08.2026 SB2026081137
#VU141450 - Deserialization of Untrusted Data
CVE-2026-18634
CWE-502 Low
No
No
9.5.2 11.08.2026 SB2026081137
#VU89082 - Use of Hard-coded Password
CVE-2024-29011
CWE-259 High
No
No
9.4.0 9.4-9400.1040 01.05.2024 SB2024050107
#VU89081 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-29010
CWE-611 Medium
No
No
9.4.0 9.4-9400.1040 01.05.2024 SB2024050107
#VU78345 - Authentication Bypass by Primary Weakness
CVE-2023-34137
CWE-305 High
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78344 - Unrestricted Upload of File with Dangerous Type
CVE-2023-34136
CWE-434 High
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78343 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-34135
CWE-22 Medium
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78342 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34134
CWE-200 Medium
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78341 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-34133
CWE-89 High
Available
No
9.3-9330 18.07.2023 SB2023071818
#VU78340 - Use of Password Hash Instead of Password for Authentication
CVE-2023-34132
CWE-836 Medium
Available
No
9.3-9330 18.07.2023 SB2023071818
#VU78339 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34131
CWE-200 Medium
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78338 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2023-34130
CWE-327 Medium
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78337 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-34129
CWE-22 Medium
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78336 - Password in Configuration File
CVE-2023-34128
CWE-260 Low
No
No
9.3-9330 18.07.2023 SB2023071818
#VU78335 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34127
CWE-78 Medium
Available
No
9.3-9330 18.07.2023 SB2023071818
#VU78330 - Use of Hard-coded Cryptographic Key
CVE-2023-34123
CWE-321 Medium
No
No
9.3-9330 18.07.2023 SB2023071818


Showing elements 1 - 20 out of 26