Tz350

Vendor:

First CVE: Jun 14, 2021 · Active for 5 years

23
Total CVEs
More Total CVEs than 88% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
4.3%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tz350 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2021
5 years ago
Most Recent CVE
Apr 29, 2026
86 days ago

CVE Severity & Scoring

Tz35023 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (87.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (13.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None20 (87.0%)
Unknown0 (0.0%)
Required3 (13.0%)
Privileges Required
Low11 (47.8%)
High1 (4.3%)
None11 (47.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditi
Aug 23, 20249.879YESNO
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
Oct 12, 20216.146NOYES
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
Apr 29, 20268.035NONO
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
Apr 29, 20266.830NONO
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code
Jan 10, 20228.828NONO
A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in
Jan 10, 20228.828NONO
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
Apr 29, 20264.925NONO
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
Oct 17, 20238.825NONO
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, se
Apr 15, 20237.525NONO
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
Mar 2, 20238.825NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
1 CVE
4.3% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
1 CVE
4.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Tz350

Top CWEs

Versions

No cataloged versions.