Sohow

Vendor:

First CVE: Mar 2, 2023 · Active for 3 years

14
Total CVEs
More Total CVEs than 91% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sohow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2023
3 years ago
Most Recent CVE
Apr 29, 2026
86 days ago

CVE Severity & Scoring

Sohow14 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (14.3%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required2 (14.3%)
Privileges Required
Low9 (64.3%)
High1 (7.1%)
None4 (28.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditi
Aug 23, 20249.879YESNO
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
Apr 29, 20268.035NONO
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
Apr 29, 20266.830NONO
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
Apr 29, 20264.925NONO
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
Oct 17, 20238.825NONO
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
Mar 2, 20238.825NONO
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
Oct 17, 20237.522NONO
SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.
Oct 17, 20236.520NONO
SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash.
Oct 17, 20236.520NONO
SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash.
Oct 17, 20236.520NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CWEs

Versions

No cataloged versions.