SonicWall SMA 200 Firmware 10.2.1.2-24sv

CPE Details

SonicWall SMA 200 Firmware 10.2.1.2-24sv
10.2.1.2-24sv
2021-12-09
19h51 +00:00
2021-12-14
17h48 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:o:sonicwall:sma_200_firmware:10.2.1.2-24sv:*:*:*:*:*:*:*

Informations

Vendor

sonicwall

Product

sma_200_firmware

Version

10.2.1.2-24sv

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-22395 2024-02-23 23h37 +00:00 Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
6.3
Moyen
CVE-2023-5970 2023-12-05 20h20 +00:00 Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
8.8
Haute
CVE-2023-44221 2023-12-05 20h10 +00:00 Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
7.2
Haute
CVE-2022-2915 2022-08-26 18h30 +00:00 A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions.
8.8
Haute
CVE-2021-20050 2021-12-23 00h20 +00:00 An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
7.5
Haute
CVE-2021-20049 2021-12-23 00h20 +00:00 A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
7.5
Haute
CVE-2021-20038 2021-12-08 09h55 +00:00 A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.
9.8
Critique