Known vulnerabilities in SonicOS - page 3
Vendor:
SonicWall
Software:
SonicOS
Software CPE:
cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*
Website:
https://www.sonicwall.com/
Total vulnerabilities:
58
Public exploits:
5
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
8.2.2-8015
7.3.3-7015
8.2.1-8010
6.5.5.2-28n
8.2.0-8009
8.1.0-8017
7.3.2-7010
7.0.1-5169
8.0.3-8011
7.3.1-7013
8.0.2-8011
7.3.0-7012
8.0.1-8017
7.2.0-7015
6.5.4.v-21s-RC2457
6.5.4.4-44v-21-2395
6.5.4.4-44v-21-2457
6.5.4.4-44v-21-2472
8.0.0-8037
7.1.3-7015
7.0.1-5165
6.5.5.1-6n
8.0.0-8035
7.1.2-7019
7.0.1-5161
6.5.4.15-117n
6.5.4.15.116n
6.5.2.8-2n
5.9.2.14-13o
7.0.1-5035
6.5.4.14-109n
5.9.2.14-12o
6.5.4.14-107n
6.5.4.v_21s_RC2395
7.1.1-7051
7.0.1-5151
7.1.1-7047
7.1.1-7040
6.5.4.13-105n
6.5.4.4-44v-21-2340
7.0.1-5145
6.5.4.11-97n
7.0.1-5111
6.5.4.4-44v-21-1551
7.0.1-5083
7.0.1-5095
7.0.1-5051-R2624
7.0.1.0-5051-1511
7.0.1.0-5051-R843
6.5.4.10-95n
7.0.1-5030-R2007
7.0.1.0-5030-1391
7.0.1-5030-R780
6.5.4.9-93n
6.5.4.4-44v-21-1519
7.0.1-5030-HF-R844
7.0.1-5051
7.0.1-5050
6.5.4.4-44V-21-1452
6.5.4.9-92n
6.5.4.8
7.0.1-R146
6.5.1.13-1n
7.0.1-5023-1349
7.0.1-5018-R1715
5.9.1.13
6.5.1.12
6.5.4.7
7.0.1-R1262
6.5.4.4-44v-21-1288
7.0.1-R1283
7.0.1-R1282
7.0.1-R1456
7.0.0-R906
7.0.0.376
7.0.1-R1036
7.0.0-R713
6.5.1.12-3n
6.5.4.4-44v-21-955
6.5.4.v_21s-1288
6.5.4.8-89n
7.0.1-R579
5.9.2.13-7n
5.9.2.7-5n
6.5.4.7-83n
7 7.0.0.0-2
6.5.4.v-21s-987
6.0.5.3-94o
6.5.1.12-1n
7.0
6.5
6.0
5.9
Vulnerabilities (58)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU59236 - Stack-based buffer overflow CVE-2021-20048 |
CWE-121 | High | 6.5.4.4-44V-21-1452, 6.5.4.9-92n | 05.01.2022 |
SB2022010525 |
||
| #VU59235 - Stack-based buffer overflow CVE-2021-20046 |
CWE-121 | High | 6.5.4.9-92n | 05.01.2022 |
SB2022010525 |
||
| #VU57238 - Improper Neutralization of HTTP Headers for Scripting Syntax CVE-2021-20031 |
CWE-644 | Low | 6.5.1.13-1n, 6.5.4.v_21s-1288, 6.5.4.8-89n, 7.0.1-R1456, 7.0.1-5018-R1715, 7.0.1-5023-1349 | 12.10.2021 |
SB2021101206 |
||
| #VU54315 - Missing release of memory after effective lifetime CVE-2021-20019 |
CWE-401 | Medium | 6.5.4.4-44v-21-1288, 6.5.4.8-89n, 7.0.0-R906, 7.0.0.376, 7.0.1-R579, 7.0.1-R1282, 7.0.1-R1283, 7.0.1-R1456 | 22.06.2021 |
SB2021062227 |
||
| #VU54104 - Memory corruption CVE-2021-20027 |
CWE-119 | Medium | 6.5.4.v_21s-1288, 6.5.4.8-89n, 7.0.1-R579 | 15.06.2021 |
SB2021061501 |
||
| #VU51733 - NULL Pointer Dereference CVE-2021-3449 |
CWE-476 | Medium | 7.0.1-R1456 | 25.03.2021 |
SB2021032518 SB2021032602 SB2021032617 and 56 more |
||
| #VU51732 - Security Features CVE-2021-3450 |
CWE-254 | Medium | 7.0.1-R1456 | 25.03.2021 |
SB2021032518 SB2021032602 SB2021032617 and 50 more |
||
| #VU47681 - Memory corruption CVE-2020-5133 |
CWE-119 | High | 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47682 - Exposure of sensitive information to an unauthorized actor CVE-2020-5143 |
CWE-200 | Low | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47683 - Out-of-bounds read CVE-2020-5134 |
CWE-125 | Medium | 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47684 - Memory corruption CVE-2020-5135 |
CWE-119 | Critical | 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47685 - Memory corruption CVE-2020-5136 |
CWE-119 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47686 - Memory corruption CVE-2020-5137 |
CWE-119 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47687 - Heap-based Buffer Overflow CVE-2020-5138 |
CWE-122 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47688 - Untrusted Pointer Dereference CVE-2020-5139 |
CWE-822 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47689 - Out-of-bounds read CVE-2020-5140 |
CWE-125 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47690 - Improper Control of Interaction Frequency CVE-2020-5141 |
CWE-799 | Medium | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47691 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5142 |
CWE-79 | Medium | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
Showing elements 41 - 60 out of 58