Known vulnerabilities in SonicWall SMA 1000

Vendor: SonicWall
Software CPE: cpe:2.3:h:sonicwall:sma_1000:*:*:*:*:*:*:*:*
Total vulnerabilities: 18
Public exploits: 3
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SonicWall SMA 1000 SonicWall SMA 1000 is affected by 18 known vulnerabilities: 2 critical, 6 high, 1 medium, 9 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137578 - Server-Side Request Forgery (SSRF)
CVE-2026-15409
CWE-918 Critical
Available
Exploited
12.4.3-03453, 12.5.0-02835 15.07.2026 SB2026071507
#VU137579 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-15410
CWE-94 High
No
Exploited
12.4.3-03453, 12.5.0-02835 15.07.2026 SB2026071507
#VU125516 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-4112
CWE-89 Low
No
No
12.4.3-03387, 12.5.0-02624 08.04.2026 SB20260408177
#VU125517 - Observable Response Discrepancy
CVE-2026-4113
CWE-204 Low
No
No
12.4.3-03387, 12.5.0-02624 08.04.2026 SB20260408177
#VU125518 - Improper Handling of Unicode Encoding
CVE-2026-4114
CWE-176 Low
No
No
12.4.3-03387, 12.5.0-02624 08.04.2026 SB20260408177
#VU125519 - Improper Handling of Unicode Encoding
CVE-2026-4116
CWE-176 Low
No
No
12.4.3-03387, 12.5.0-02624 08.04.2026 SB20260408177
#VU120180 - Missing Authorization
CVE-2025-40602
CWE-862 High
No
Exploited
12.4.3-03245, 12.5.0-02283 17.12.2025 SB2025121748
#VU109189 - Server-Side Request Forgery (SSRF)
CVE-2025-40595
CWE-918 High
No
No
12.4.3-02963 14.05.2025 SB2025051463
#VU108094 - Server-Side Request Forgery (SSRF)
CVE-2025-2170
CWE-918 High
No
No
12.4.3-02925 30.04.2025 SB2025043043
#VU103262 - Deserialization of Untrusted Data
CVE-2025-23006
CWE-502 Critical
No
Exploited
12.4.3-02854 23.01.2025 SB2025012331
#VU98495 - Server-Side Request Forgery (SSRF)
CVE-2024-45317
CWE-918 Medium
No
No
12.4.3-02676 14.10.2024 SB2024101458
#VU71724 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-0126
CWE-22 High
No
No
12.4.2-05352 01.02.2023 SB2023020115
#VU63314 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-1702
CWE-601 Low
No
No
12.4.1-02994 17.05.2022 SB2022051721
#VU63313 - Use of Hard-coded Cryptographic Key
CVE-2022-1701
CWE-321 Low
No
No
12.4.1-02994 17.05.2022 SB2022051721
#VU63302 - Improper Access Control
CVE-2022-22282
CWE-284 High
No
No
12.4.1-02994 17.05.2022 SB2022051721
#VU61110 - Use of Uninitialized Resource
CVE-2022-0847
CWE-908 Low
Available
Exploited
12.4.2-05082 08.03.2022 SB2022030808
SB2022031019
SB2022031026
and 27 more
#VU60355 - NULL Pointer Dereference
CWE-476 Low
No
No
12.4.1-02873 07.02.2022 SB2022020712
#VU55143 - Integer overflow
CVE-2021-33909
CWE-190 Low
Available
No
12.4.2-05082 21.07.2021 SB2021072106
SB2021072222
SB2021072223
and 63 more