Known vulnerabilities in SonicWall SMA 1000 12.4.1-02994
Vendor:
SonicWall
Software:
SonicWall SMA 1000
Version:
12.4.1-02994
Software CPE:
cpe:2.3:h:sonicwall:sma_1000:*:*:*:*:*:*:*:*
Website:
https://www.sonicwall.com/
Total vulnerabilities:
9
Public exploits:
2
Known exploited (KEV):
2
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125516 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-4112 |
CWE-89 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU125517 - Observable Response Discrepancy CVE-2026-4113 |
CWE-204 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU125518 - Improper Handling of Unicode Encoding CVE-2026-4114 |
CWE-176 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU125519 - Improper Handling of Unicode Encoding CVE-2026-4116 |
CWE-176 | Low | 12.4.3-03387, 12.5.0-02624 | 08.04.2026 |
SB20260408177 |
||
| #VU120180 - Missing Authorization CVE-2025-40602 |
CWE-862 | High | 12.4.3-03245, 12.5.0-02283 | 17.12.2025 |
SB2025121748 |
||
| #VU109189 - Server-Side Request Forgery (SSRF) CVE-2025-40595 |
CWE-918 | High | 12.4.3-02963 | 14.05.2025 |
SB2025051463 |
||
| #VU108094 - Server-Side Request Forgery (SSRF) CVE-2025-2170 |
CWE-918 | High | 12.4.3-02925 | 30.04.2025 |
SB2025043043 |
||
| #VU61110 - Use of Uninitialized Resource CVE-2022-0847 |
CWE-908 | Low | 12.4.2-05082 | 08.03.2022 |
SB2022030808 SB2022031019 SB2022031026 and 27 more |
||
| #VU55143 - Integer overflow CVE-2021-33909 |
CWE-190 | Low | 12.4.2-05082 | 21.07.2021 |
SB2021072106 SB2021072222 SB2021072223 and 63 more |