📦 Sonicos

by Sonicwall

🔍 What is Sonicos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-40600

CRITICAL CVSS 9.8 Jul 29, 2025

A format string vulnerability in SonicOS SSL VPN interface allows remote unauthenticated attackers to execute arbitrary code or cause denial of service by sending specially crafted requests. This affe...

CVE-2024-40766

CRITICAL CVSS 9.8 Aug 23, 2024

An improper access control vulnerability in SonicWall SonicOS management interface allows attackers to bypass authentication and access restricted resources. In worst cases, it can cause firewall cras...

CVE-2024-3596

CRITICAL CVSS 9.0 Jul 9, 2024

CVE-2024-3596 allows a local attacker to forge RADIUS protocol responses by exploiting MD5 collisions, enabling them to modify authentication outcomes. This affects any system using RADIUS under RFC 2...

CVE-2024-22394

CRITICAL CVSS 9.8 Feb 8, 2024

An improper authentication vulnerability in SonicWall SonicOS SSL-VPN allows remote attackers to bypass authentication under specific conditions. This affects organizations using SonicWall firewalls w...

CVE-2022-22274

CRITICAL CVSS 9.8 Mar 25, 2022

CVE-2022-22274 is a critical stack-based buffer overflow vulnerability in SonicOS firewalls that allows remote unauthenticated attackers to trigger denial of service or potentially execute arbitrary c...

CVE-2020-5135

CRITICAL CVSS 9.8 Oct 12, 2020

CVE-2020-5135 is a critical buffer overflow vulnerability in SonicOS firewalls that allows remote attackers to cause denial of service or potentially execute arbitrary code by sending malicious reques...

CVE-2025-40601

HIGH CVSS 7.5 Nov 20, 2025

A stack-based buffer overflow vulnerability in SonicOS SSLVPN service allows remote unauthenticated attackers to cause denial of service by crashing affected firewalls. This affects SonicWall firewall...

CVE-2024-29012

HIGH CVSS 7.5 Jun 20, 2024

A stack-based buffer overflow vulnerability in SonicOS HTTP server allows authenticated remote attackers to cause Denial of Service (DoS) by exploiting improper bounds checking in the sscanf function....

CVE-2023-41713

HIGH CVSS 7.5 Oct 17, 2023

CVE-2023-41713 is a hard-coded password vulnerability in SonicWall SonicOS affecting the 'dynHandleBuyToolbar' demo function. This allows attackers to bypass authentication and potentially gain admini...

CVE-2023-0656

HIGH CVSS 7.5 Mar 2, 2023

A stack-based buffer overflow vulnerability in SonicOS allows remote unauthenticated attackers to trigger a denial of service by crashing affected firewalls. This affects SonicWall firewalls running v...

CVE-2022-22275

HIGH CVSS 7.5 Apr 27, 2022

This vulnerability in SonicWall firewalls allows attackers to bypass security policies by sending TCP traffic through HTTP/S channels from WAN to DMZ before TCP handshake completion. This could lead t...

CVE-2021-20046

HIGH CVSS 8.8 Jan 10, 2022

A stack-based buffer overflow vulnerability in SonicOS firewalls allows remote authenticated attackers to cause denial of service and potentially execute arbitrary code by sending specially crafted HT...

CVE-2021-20019

HIGH CVSS 7.5 Jun 23, 2021

CVE-2021-20019 is a memory disclosure vulnerability in SonicOS HTTP servers where crafted HTTP requests can leak partial memory contents. This could expose sensitive internal data like credentials, se...

CVE-2021-3450

HIGH CVSS 7.4 Mar 25, 2021

This OpenSSL vulnerability allows certificate chain validation to be bypassed when the X509_V_FLAG_X509_STRICT flag is explicitly set. It affects applications using OpenSSL 1.1.1h-1.1.1j that enable s...

CVE-2026-0401

MEDIUM CVSS 4.9 Feb 24, 2026

A post-authentication NULL pointer dereference vulnerability in SonicOS firewalls allows authenticated remote attackers to cause a denial of service by crashing the firewall. This affects organization...

CVE-2026-0399

MEDIUM CVSS 4.9 Feb 24, 2026

This CVE describes post-authentication stack-based buffer overflow vulnerabilities in SonicOS management interfaces. Attackers with valid credentials can exploit improper bounds checking in an API end...