Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
History

Thu, 06 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall sma 200
Sonicwall sma 200 Firmware
Sonicwall sma 210
Sonicwall sma 210 Firmware
Sonicwall sma 400
Sonicwall sma 400 Firmware
Sonicwall sma 410
Sonicwall sma 410 Firmware
Sonicwall sma 500v
Sonicwall sma 500v Firmware
CPEs cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sonicwall sma 200
Sonicwall sma 200 Firmware
Sonicwall sma 210
Sonicwall sma 210 Firmware
Sonicwall sma 400
Sonicwall sma 400 Firmware
Sonicwall sma 410
Sonicwall sma 410 Firmware
Sonicwall sma 500v
Sonicwall sma 500v Firmware

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00144}

epss

{'score': 0.00207}


Thu, 05 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall sma100 Firmware
CPEs cpe:2.3:o:sonicwall:sma100_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sonicwall
Sonicwall sma100 Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 13:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published: 2024-12-05T13:39:19.644Z

Updated: 2024-12-07T04:55:28.515Z

Reserved: 2024-07-10T15:58:49.461Z

Link: CVE-2024-40763

cve-icon Vulnrichment

Updated: 2024-12-05T16:51:54.353Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-05T14:15:20.850

Modified: 2025-11-06T16:43:04.740

Link: CVE-2024-40763

cve-icon Redhat

No data.