Skip to main content

SonicOS vulnerabilities

3 published alerts for SonicWall SonicOS.

Actively exploited (KEV)Ransomware

CVE-2024-53704

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-53704). SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. CISA remediation due date: 2025-03-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-40766

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-40766). SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-5135

SonicWall SonicOS Buffer Overflow Vulnerability

SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-5135). A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.