CVE-2024-40763

Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

History

06 Nov 2025, 16:43

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de desbordamiento de búfer basado en montón en SonicWall SMA100 SSLVPN debido al uso de strcpy. Esto permite a atacantes remotos autenticados provocar un desbordamiento de búfer basado en montón y potencialmente provocar la ejecución de código.
First Time Sonicwall sma 210 Firmware
Sonicwall sma 400
Sonicwall sma 210
Sonicwall sma 200
Sonicwall sma 410 Firmware
Sonicwall sma 500v Firmware
Sonicwall sma 500v
Sonicwall
Sonicwall sma 410
Sonicwall sma 400 Firmware
Sonicwall sma 200 Firmware
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0018 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0018 - Vendor Advisory
CPE cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*

05 Dec 2024, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

05 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-05 14:15

Updated : 2025-11-06 16:43


NVD link : CVE-2024-40763

Mitre link : CVE-2024-40763

CVE.ORG link : CVE-2024-40763


JSON object : View

Products Affected

sonicwall

  • sma_400
  • sma_200_firmware
  • sma_400_firmware
  • sma_500v_firmware
  • sma_210
  • sma_210_firmware
  • sma_200
  • sma_410
  • sma_410_firmware
  • sma_500v
CWE
CWE-122

Heap-based Buffer Overflow