SonicWall Secure Mobile Access 100
Our sources currently list 42 known vulnerabilities affecting SonicWall Secure Mobile Access 100. 10 are rated critical severity. 8 of 42 are actively exploited according to CISA, the most recent added 1 May 2025.
Last updated: 22 July 2026, 20:37 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2024-38475 | Critical (9.1) | Actively exploited | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the se… | |
| CVE-2021-20038 | Critical (9.8) | Actively exploited · ransomware | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute cod… | |
| CVE-2019-7481 | High (7.5) | Actively exploited · ransomware | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier. | |
| CVE-2023-44221 | High (7.2) | Actively exploited | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary comm… | |
| CVE-2021-20016 | Critical (9.8) | Actively exploited · ransomware | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session rel… | |
| CVE-2021-20028 | Critical (9.8) | Actively exploited · ransomware | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running a… | |
| CVE-2021-20035 | Medium (6.5) | Actively exploited | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentia… | |
| CVE-2019-7483 | High (7.5) | Actively exploited | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | |
| CVE-2021-20034 | Critical (9.1) | Elevated likelihood (81%) | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting i… | |
| CVE-2021-20039 | High (8.8) | Elevated likelihood (78%) | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary comma… | |
| CVE-2025-40596 | High (7.3) | Elevated likelihood (56%) | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in co… | |
| CVE-2025-40598 | Medium (6.1) | Elevated likelihood (53%) | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScri… | |
| CVE-2021-20044 | High (8.8) | Elevated likelihood (40%) | A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnera… | |
| CVE-2025-32821 | High (7.2) | Elevated likelihood (32%) | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the a… | |
| CVE-2025-40597 | High (7.5) | Elevated likelihood (28%) | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in cod… | |
| CVE-2021-20040 | High (7.5) | Elevated likelihood (26%) | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerab… | |
| CVE-2021-20045 | Critical (9.8) | Elevated likelihood (25%) | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in … | |
| CVE-2021-20043 | High (8.8) | Elevated likelihood (23%) | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appl… | |
| CVE-2024-53703 | High (8.1) | Elevated likelihood (13%) | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stac… | |
| CVE-2025-40599 | Critical (9.1) | Elevated likelihood (12%) | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw t… | |
| CVE-2022-1703 | High (8.8) | Elevated likelihood (11%) | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potential… | |
| CVE-2019-7482 | Critical (9.8) | No exploitation reported | Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 a… | |
| CVE-2025-32819 | High (8.8) | No exploitation reported | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting … | |
| CVE-2021-20041 | High (7.5) | No exploitation reported | An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with un… | |
| CVE-2025-32820 | High (8.8) | No exploitation reported | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writabl… | |
| CVE-2021-20042 | Critical (9.8) | No exploitation reported | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400… | |
| CVE-2022-22273 | Critical (9.8) | No exploitation reported | Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of S… | |
| CVE-2020-5146 | High (7.2) | No exploitation reported | A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 … | |
| CVE-2019-7486 | High (8.8) | No exploitation reported | Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier. | |
| CVE-2019-7485 | High (8.8) | No exploitation reported | Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier… | |
| CVE-2022-2915 | High (8.8) | No exploitation reported | A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially… | |
| CVE-2021-20049 | High (7.5) | No exploitation reported | A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerab… | |
| CVE-2022-22279 | Medium (4.9) | No exploitation reported | A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 seri… | |
| CVE-2024-45318 | High (8.1) | No exploitation reported | A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution. | |
| CVE-2024-40763 | High (7.5) | No exploitation reported | Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and… | |
| CVE-2023-5970 | High (8.8) | No exploitation reported | Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resu… | |
| CVE-2021-20050 | High (7.5) | No exploitation reported | An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration… | |
| CVE-2019-7484 | Medium (6.5) | No exploitation reported | Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 versio… | |
| CVE-2025-40603 | Medium (4.5) | No exploitation reported | A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view p… | |
| CVE-2024-22395 | Medium (6.3) | No exploitation reported | Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated … | |
| CVE-2024-53702 | Medium (5.3) | No exploitation reported | Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by a… | |
| CVE-2024-45319 | Medium (6.3) | No exploitation reported | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement duri… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
8 of these are being actively exploited right now.
Our Newcastle team can audit your SonicWall estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
