Netextender
Vendor:
First CVE: Aug 26, 2015 · Active for 10 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Netextender over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2015
10 years ago
Most Recent CVE
Jul 18, 2024
737 days ago
CVE Severity & Scoring
Netextender9 CVEs
33%
67%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (77.8%)
Network1 (11.1%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None7 (77.8%)
Unknown1 (11.1%)
Required1 (11.1%)
Privileges Required
Low8 (88.9%)
High0 (0.0%)
None0 (0.0%)
Unknown1 (11.1%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29014HIGH Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Cli | Jul 18, 2024 | 8.8 | 29 | NO | NO |
CVE-2022-22281HIGH A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbi | May 13, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-5131HIGH SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host | Jul 17, 2020 | 7.8 | 25 | NO | NO |
CVE-2023-44218HIGH
A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading | Oct 3, 2023 | 7.8 | 23 | NO | NO |
CVE-2020-5147MEDIUM SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This | Jan 9, 2021 | 5.3 | 23 | NO | YES |
CVE-2023-44220HIGH SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exp | Oct 27, 2023 | 7.3 | 21 | NO | NO |
CVE-2023-44217HIGH
A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privile | Oct 3, 2023 | 7.8 | 19 | NO | NO |
CVE-2015-4173MEDIUM Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40 | Aug 26, 2015 | 6.9 | 19 | NO | NO |
CVE-2023-6340MEDIUM SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnera | Jan 18, 2024 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Netextender
Top CWEs
Versions
No cataloged versions.