SonicWall Security Advisories & CVEs
23 advisories tracked · SonicWall PSIRT (PSIRT@sonicwall.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor SonicWall CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your SonicWall device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in SonicWall's recent advisories.
Official source
SonicWall PSIRT (PSIRT@sonicwall.com CNA) via NVD
SonicWall is its own CVE Numbering Authority. Its PSIRT portal (psirt.global.sonicwall.com) is a reCAPTCHA-gated JavaScript app with no stable public feed, so VulniPulse ingests SonicWall's CVEs from the NVD CNA feed (PSIRT@sonicwall.com), grouped by the official SNWLID advisory, with affected products and versions from each description and a link back to the SNWLID advisory. Covers SonicOS firewalls (Gen6/Gen7 TZ/NSa/NSsp/NSv), Secure Mobile Access (SMA 100/1000), SSL-VPN, NetExtender, Email Security and GMS/Analytics — SonicWall SSL-VPN is a frequent ransomware entry point.
Latest SonicWall advisories
Unknown [CVE-2021-20021] vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Unknown [CVE-2021-20016] SonicWall SMA100: SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x. Affected product named by the advisory: SonicWall SMA100.
Unknown [CVE-2019-7481] Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.