Known Vulnerabilities for Sma 400 by Sonicwall
Listed below are 10 of the newest known vulnerabilities associated with "Sma 400" by "Sonicwall".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Sonicwall Sma 400
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-22273 | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of Special Elements leading to OS Command Injection vulnerability imp... | 9.8 - CRITICAL | 2022-03-17 | 2023-11-07 |
| CVE-2021-20043 | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to ... | 8.8 - HIGH | 2021-12-08 | 2021-12-10 |
| CVE-2021-20042 | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewa... | 9.8 - CRITICAL | 2021-12-08 | 2023-06-26 |
| CVE-2021-20041 | An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /file... | 7.5 - HIGH | 2021-12-08 | 2021-12-10 |
| CVE-2021-20040 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload craft... | 7.5 - HIGH | 2021-12-08 | 2021-12-10 |
| CVE-2021-20039 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a ... | 8.8 - HIGH | 2021-12-08 | 2022-04-01 |
| CVE-2021-20038 | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a rem... | 9.8 - CRITICAL | 2021-12-08 | 2022-05-13 |
| CVE-2021-20035 | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inje... | 6.5 - MEDIUM | 2021-09-27 | 2021-10-06 |
| CVE-2021-20034 | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal chec... | 9.1 - CRITICAL | 2021-09-27 | 2022-07-08 |
| CVE-2021-20016 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL ... | 9.8 - CRITICAL | 2021-02-04 | 2021-02-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sonicwall | Sma 400 | - | All | All | All |