SonicWall SonicOS
Our sources currently list 68 known vulnerabilities affecting SonicWall SonicOS. 12 are rated critical severity. 3 of 68 are actively exploited according to CISA, the most recent added 18 February 2025.
Last updated: 22 July 2026, 20:36 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2024-53704 | Critical (9.8) | Actively exploited · ransomware | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | |
| CVE-2020-5135 | Critical (9.8) | Actively exploited | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the fi… | |
| CVE-2024-40766 | Critical (9.8) | Actively exploited · ransomware | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditi… | |
| CVE-2019-12257 | High (8.8) | Elevated likelihood (84%) | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh… | |
| CVE-2019-12255 | Critical (9.8) | Elevated likelihood (75%) | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | |
| CVE-2021-3449 | Medium (5.9) | Elevated likelihood (63%) | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms… | |
| CVE-2022-22274 | Critical (9.8) | Elevated likelihood (57%) | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code… | |
| CVE-2019-12265 | Medium (5.3) | Elevated likelihood (55%) | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 … | |
| CVE-2023-0656 | High (7.5) | Elevated likelihood (41%) | A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to cras… | |
| CVE-2019-12256 | Critical (9.8) | Elevated likelihood (27%) | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | |
| CVE-2019-12258 | High (7.5) | Elevated likelihood (23%) | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | |
| CVE-2019-12260 | Critical (9.8) | Elevated likelihood (23%) | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma… | |
| CVE-2021-3450 | High (7.4) | Elevated likelihood (18%) | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.… | |
| CVE-2019-12259 | High (7.5) | Elevated likelihood (16%) | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP pa… | |
| CVE-2024-3596 | Critical (9.0) | Elevated likelihood (15%) | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot… | |
| CVE-2021-20031 | Medium (6.1) | Elevated likelihood (13%) | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains. | |
| CVE-2019-12261 | Critical (9.8) | No exploitation reported | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion dur… | |
| CVE-2019-12263 | High (8.1) | No exploitation reported | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race… | |
| CVE-2018-5281 | Medium (5.4) | No exploitation reported | SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens. | |
| CVE-2018-5280 | Medium (5.4) | No exploitation reported | SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens. | |
| CVE-2015-3447 | Medium (4.3) | No exploitation reported | Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML … | |
| CVE-2021-20046 | High (8.8) | No exploitation reported | A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in … | |
| CVE-2021-20048 | High (8.8) | No exploitation reported | A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code … | |
| CVE-2020-5138 | High (7.5) | No exploitation reported | A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash. Th… | |
| CVE-2020-5139 | High (7.5) | No exploitation reported | A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall cr… | |
| CVE-2020-5140 | High (7.5) | No exploitation reported | A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads t… | |
| CVE-2020-5133 | High (7.5) | No exploitation reported | A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall crash. This vulnerability affected … | |
| CVE-2020-5137 | High (7.5) | No exploitation reported | A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to firewall crash. Thi… | |
| CVE-2020-5143 | Medium (5.3) | No exploitation reported | SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerabili… | |
| CVE-2021-20019 | High (7.5) | No exploitation reported | A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure… | |
| CVE-2019-7475 | Critical (9.8) | No exploitation reported | A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced routing services. This vulnera… | |
| CVE-2021-20027 | High (7.5) | No exploitation reported | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Ge… | |
| CVE-2020-5141 | Medium (6.5) | No exploitation reported | A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen … | |
| CVE-2020-5130 | Medium (5.3) | No exploitation reported | SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS v… | |
| CVE-2019-7477 | High (7.5) | No exploitation reported | A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are enabled. This vulnerability af… | |
| CVE-2025-40601 | High (7.5) | No exploitation reported | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted f… | |
| CVE-2020-5134 | Medium (6.5) | No exploitation reported | A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a firewall crash. This vulnerability affected SonicOS Gen 6 versio… | |
| CVE-2020-5136 | Medium (6.5) | No exploitation reported | A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assist portal, which leads to a firewall cra… | |
| CVE-2020-5142 | Medium (6.1) | No exploitation reported | A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary J… | |
| CVE-2022-22275 | High (7.5) | No exploitation reported | Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service… | |
| CVE-2019-7479 | High (7.2) | No exploitation reported | A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earl… | |
| CVE-2020-5132 | Medium (5.3) | No exploitation reported | SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly … | |
| CVE-2025-40600 | Critical (9.8) | No exploitation reported | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. | |
| CVE-2023-39276 | Medium (6.5) | No exploitation reported | SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. | |
| CVE-2023-39277 | Medium (6.5) | No exploitation reported | SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash. | |
| CVE-2023-39278 | Medium (6.5) | No exploitation reported | SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash. | |
| CVE-2023-39279 | Medium (6.5) | No exploitation reported | SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash. | |
| CVE-2023-39280 | Medium (6.5) | No exploitation reported | SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash. | |
| CVE-2023-41711 | Medium (6.5) | No exploitation reported | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash. | |
| CVE-2023-41712 | Medium (6.5) | No exploitation reported | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash. |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
3 of these are being actively exploited right now.
Our Newcastle team can audit your SonicWall estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
