SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash.
📦
sohow
Vendor: sonicwall
Actively Exploited
1
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
7
Remote Access
Total CVEs
14
Total Indexed
Avg. EPSS
1.75%
Exploit Prob.
Security Vulnerability Index
Page 2 / 2
6.5
CVSS
CVE-2023-39278
RCE
Severity: MEDIUM
6.5
CVSS
CVE-2023-39277
RCE
SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.
Severity: MEDIUM
6.5
CVSS
CVE-2023-39276
RCE
SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
Severity: MEDIUM
8.8
CVSS
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
Severity: HIGH