📦 Sma 400 Firmware

by Sonicwall

🔍 What is Sma 400 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-22273

CRITICAL CVSS 9.8 Mar 17, 2022

This CVE allows attackers to execute arbitrary operating system commands on vulnerable SonicWall Secure Remote Access (SRA) and Secure Mobile Access (SMA) appliances through improper input sanitizatio...

CVE-2021-20042

CRITICAL CVSS 9.8 Dec 8, 2021

CVE-2021-20042 allows unauthenticated remote attackers to use SonicWall SMA 100 series appliances as unintended proxies to bypass firewall rules. This affects SMA 200, 210, 400, 410, and 500v applianc...

CVE-2021-20045

CRITICAL CVSS 9.8 Dec 8, 2021

A buffer overflow vulnerability in SonicWall SMA appliances allows remote unauthenticated attackers to execute arbitrary code as the 'nobody' user. This affects SMA 200, 210, 400, 410, and 500v applia...

CVE-2021-20038

CRITICAL CVSS 9.8 Dec 8, 2021

A stack-based buffer overflow vulnerability in SonicWall SMA 100 series appliances' Apache httpd mod_cgi module allows remote unauthenticated attackers to execute arbitrary code as the 'nobody' user. ...

CVE-2021-20034

CRITICAL CVSS 9.1 Sep 27, 2021

CVE-2021-20034 is an improper access control vulnerability in SonicWall SMA100 appliances that allows unauthenticated attackers to bypass path traversal checks and delete arbitrary files. This could l...

CVE-2025-32819

HIGH CVSS 8.8 May 7, 2025

This vulnerability allows authenticated SSLVPN users on SMA100 devices to bypass path traversal protections and delete arbitrary files. Attackers could force a factory reset, causing service disruptio...

CVE-2025-32821

HIGH CVSS 7.2 May 7, 2025

A command injection vulnerability in SMA100 SSL-VPN appliances allows authenticated administrators to execute arbitrary shell commands by manipulating file upload parameters. This affects organization...

CVE-2024-53703

HIGH CVSS 8.1 Dec 5, 2024

A stack-based buffer overflow vulnerability in SonicWall SMA100 SSLVPN firmware's mod_httprp library allows remote attackers to potentially execute arbitrary code. This affects SMA100 appliances runni...

CVE-2024-45318

HIGH CVSS 8.1 Dec 5, 2024

A stack-based buffer overflow vulnerability in SonicWall SMA100 SSLVPN web management interface allows remote attackers to execute arbitrary code on affected devices. This affects organizations using ...

CVE-2023-5970

HIGH CVSS 8.8 Dec 5, 2023

This vulnerability allows a remote authenticated attacker to bypass multi-factor authentication (MFA) on SonicWall SMA100 SSL-VPN virtual office portals by creating duplicate external domain users usi...

CVE-2021-20049

HIGH CVSS 7.5 Dec 23, 2021

CVE-2021-20049 is a username enumeration vulnerability in SonicWall SMA100's password change API that allows unauthenticated attackers to determine valid usernames by analyzing server responses. This ...

CVE-2021-20044

HIGH CVSS 8.8 Dec 8, 2021

A post-authentication remote command injection vulnerability in SonicWall SMA100 appliances allows authenticated attackers to execute arbitrary operating system commands on affected devices. This affe...

CVE-2021-20040

HIGH CVSS 7.5 Dec 8, 2021

A relative path traversal vulnerability in SonicWall SMA appliances allows unauthenticated remote attackers to upload arbitrary files as a low-privileged 'nobody' user. This affects SMA 200, 210, 400,...

CVE-2024-53702

MEDIUM CVSS 5.3 Dec 5, 2024

This vulnerability in SonicWall SMA100 SSLVPN devices uses a weak random number generator for backup codes, allowing attackers to potentially predict these codes. This affects organizations using vuln...