Build advisory
SonicWall 6.5.4.11-97n: known CVEs & fixed releases
13 CVEs affect this build · highest CVSS 9 · 6 builds behind the latest 6.5.5.2-28n · updated 2026-06-26
Patch path: upgrade to 6.5.5.2-28n or 7.0.1-5111 or 7.0.1-5161 or 7.1.1-7058 or 7.1.2-7019 or 7.3.1-7013 or 7.3.2-7010 or 8.0.3-8011 or 8.2.0-8009 to clear the exploited issues below.
- CRITICALCVE-2024-3596
CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
- CVSS
- 9
- EPSS
- 15%
- Published
- 2024-07-09
- HIGHCVE-2023-1101
CVE-2023-1101
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
- CVSS
- 8.8
- Published
- 2023-03-02
Fixed in7.0.1-5111NVD ↗psirt.global.sonicwall.com ↗ - HIGHCVE-2026-0204
CVE-2026-0204
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
- CVSS
- 8
- Published
- 2026-04-29
Fixed in6.5.5.2-28n,7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - HIGHCVE-2025-40601
CVE-2025-40601
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
- CVSS
- 7.5
- Published
- 2025-11-20
Fixed in7.3.1-7013,8.0.3-8011NVD ↗psirt.global.sonicwall.com ↗ - HIGHCVE-2024-29012
CVE-2024-29012
Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.
- CVSS
- 7.5
- Published
- 2024-06-20
Fixed in7.0.1-5161,7.1.1-7058,7.1.2-7019NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-0205
CVE-2026-0205
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
- CVSS
- 6.8
- Published
- 2026-04-29
Fixed in6.5.5.2-28n,7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2024-29013
CVE-2024-29013
Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
- CVSS
- 6.5
- Published
- 2024-06-20
Fixed in7.0.1-5161,7.1.1-7058,7.1.2-7019NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-0206
CVE-2026-0206
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
- CVSS
- 4.9
- Published
- 2026-04-29
Fixed in6.5.5.2-28n,7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-3439
CVE-2026-3439
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.
- CVSS
- 4.9
- Published
- 2026-03-04
Fixed in7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-0399
CVE-2026-0399
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.
- CVSS
- 4.9
- Published
- 2026-02-24
Fixed in7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-0400
CVE-2026-0400
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVSS
- 4.9
- Published
- 2026-02-24
Fixed in7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-0402
CVE-2026-0402
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVSS
- 4.9
- Published
- 2026-02-24
Fixed in7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗ - MEDIUMCVE-2026-0401
CVE-2026-0401
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVSS
- 4.9
- Published
- 2026-02-24
Fixed in7.3.2-7010,8.2.0-8009NVD ↗psirt.global.sonicwall.com ↗
Stop checking versions by hand
Is your whole fleet exposed, not just this SonicWall?
VulnMonitor reconciles every advisory against your real inventory and ranks what matters by actual exploitation (CISA KEV, EPSS), not raw CVSS. New CVE hits your gear, it is on your queue with the fix attached.
Free to start · no credit card
Other SonicWall versions
- 7.0.1-5035 and older versions 25 CVEs · 1 KEV
- 7.0.1-5035 25 CVEs · 1 KEV
- 6.5.4.4-44v-21-1551 24 CVEs · 1 KEV
- 5.9.2.14-12o and older versions 24 CVEs · 1 KEV
- 6.5.4.4-44v-21-2079 and earlier versions 23 CVEs · 1 KEV
- 7.1.1-7040 16 CVEs · 1 KEV
- 7.1.1-7051 and older versions 15 CVEs · 1 KEV
- 7.1.1-7051 and earlier versions 15 CVEs · 1 KEV
- 6.5.4.4-44v-21-2395 and older versions 14 CVEs · 1 KEV
- 7.1.2-7019 12 CVEs · 1 KEV
- 7.1.1-7058 and older versions 12 CVEs · 1 KEV
- 8.0.0-8035 11 CVEs · 1 KEV
- 7.2.0-7015 and older versions 11 CVEs
- 7.0.1-5083 24 CVEs