Known vulnerabilities in SonicOS 7.0.1-5050

Vendor: SonicWall
Software: SonicOS
Version: 7.0.1-5050
Software CPE: cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SonicOS version 7.0.1-5050 SonicOS 7.0.1-5050 is affected by 16 vulnerabilities: 2 high, 7 medium, 7 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141057 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2026-0516
CWE-644 Low
No
No
8.2.2-8015 06.08.2026 SB2026080638
#VU128470 - Weak Authentication
CVE-2026-0204
CWE-1390 High
No
No
6.5.5.2-28n, 7.3.2-7010, 8.2.0-8009 29.04.2026 SB2026042987
#VU128471 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-0205
CWE-22 Medium
No
No
6.5.5.2-28n, 7.3.2-7010, 8.2.0-8009 29.04.2026 SB2026042987
#VU128472 - Stack-based buffer overflow
CVE-2026-0206
CWE-121 Low
No
No
6.5.5.2-28n, 7.3.2-7010, 8.2.0-8009 29.04.2026 SB2026042987
#VU123199 - Out-of-bounds read
CVE-2026-0402
CWE-125 Low
No
No
7.3.2-7010, 8.2.0-8009 24.02.2026 SB2026022447
#VU123198 - NULL Pointer Dereference
CVE-2026-0401
CWE-476 Low
No
No
7.3.2-7010, 8.2.0-8009 24.02.2026 SB2026022447
#VU123197 - Use of Externally-Controlled Format String
CVE-2026-0400
CWE-134 Low
No
No
7.3.2-7010, 8.2.0-8009 24.02.2026 SB2026022447
#VU123196 - Stack-based buffer overflow
CVE-2026-0399
CWE-121 Low
No
No
7.3.2-7010, 8.2.0-8009 24.02.2026 SB2026022447
#VU118630 - Stack-based buffer overflow
CVE-2025-40601
CWE-121 Medium
No
No
7.3.1-7013, 8.0.3-8011 20.11.2025 SB2025112001
#VU72721 - Improper Authentication
CVE-2023-1101
CWE-287 Medium
No
No
7.0.1-5111 02.03.2023 SB2023030249
#VU72720 - Stack-based buffer overflow
CVE-2023-0656
CWE-121 Medium
Public exploit available
No
7.0.1-5111 02.03.2023 SB2023030249
#VU62659 - Allocation of Resources Without Limits or Throttling
CVE-2022-22278
CWE-770 Medium
No
No
6.5.4.10-95n, 7.0.1.0-5051-R843, 7.0.1.0-5051-1511, 7.0.1-5051-R2624 27.04.2022 SB2022042717
#VU62658 - Cleartext Transmission of Sensitive Information
CVE-2022-22277
CWE-319 Low
No
No
6.5.4.10-95n, 7.0.1.0-5051-R843, 7.0.1.0-5051-1511, 7.0.1-5051-R2624 27.04.2022 SB2022042717
#VU62657 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22276
CWE-200 Medium
No
No
6.5.4.10-95n, 7.0.1.0-5051-R843, 7.0.1.0-5051-1511, 7.0.1-5051-R2624 27.04.2022 SB2022042717
#VU62656 - Resource exhaustion
CVE-2022-22275
CWE-400 Medium
No
No
6.5.4.10-95n, 7.0.1.0-5051-R843, 7.0.1.0-5051-1511, 7.0.1-5051-R2624 27.04.2022 SB2022042717
#VU61613 - Stack-based buffer overflow
CVE-2022-22274
CWE-121 High
Public exploit available
No
6.5.4.4-44v-21-1519, 7.0.1-5030-HF-R844, 7.0.1-5051 25.03.2022 SB2022032502