📦

sma_500v

Vendor: sonicwall

Actively Exploited 6 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 10 Remote Access
Total CVEs 41 Total Indexed
Avg. EPSS 17.15% Exploit Prob.
Latest CVE CVE-2025-40603 Oct 31

Security Vulnerability Index

Page 1 / 5
4.5 CVSS

A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

EPSS: 0.05%
6.1 CVSS

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

EPSS: 0.32%
7.5 CVSS

A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

EPSS: 0.47%
7.3 CVSS

A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

EPSS: 0.52%
9.1 CVSS

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

EPSS: 0.73%
7.2 CVSS

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

EPSS: 0.56%
8.8 CVSS

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.

EPSS: 1.00%
8.8 CVSS

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

EPSS: 0.86%
8.1 CVSS
CVE-2024-53703
Exploit Found

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

EPSS: 29.15%
5.3 CVSS

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

EPSS: 0.37%