Refine your search

2 vulnerabilities found for Global VPN Client by SonicWall

CERTFR-2026-AVI-0990
Vulnerability from certfr_avis

Une vulnérabilité a été découverte dans SonicWall Global VPN Client. Elle permet à un attaquant de provoquer un déni de service.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
Sonicwall Global VPN Client Global VPN Client versions antérieures à 5.0.0.2008
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "Global VPN Client versions ant\u00e9rieures \u00e0 5.0.0.2008",
      "product": {
        "name": "Global VPN Client",
        "vendor": {
          "name": "Sonicwall",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-66151",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66151"
    }
  ],
  "initial_release_date": "2026-08-10T00:00:00",
  "last_revision_date": "2026-08-10T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0990",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-08-10T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service"
    }
  ],
  "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans SonicWall Global VPN Client. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service.",
  "title": "Vuln\u00e9rabilit\u00e9 dans SonicWall Global VPN Client",
  "vendor_advisories": [
    {
      "published_at": "2026-08-06",
      "title": "Bulletin de s\u00e9curit\u00e9 SonicWall SNWLID-2026-0010",
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0010"
    }
  ]
}

CVE-2026-66151 (GCVE-0-2026-66151)
Vulnerability from cvelistv5
Published
2026-08-07 20:10
Modified
2026-08-11 19:29
CWE
Summary
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Impacted products
Vendor Product Version
SonicWall Global VPN Client Version: 4.10.8.1108 and earlier versions
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-66151",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-11T19:29:26.927956Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-11T19:29:41.797Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "platforms": [
            "Windows"
          ],
          "product": "Global VPN Client",
          "vendor": "SonicWall",
          "versions": [
            {
              "status": "affected",
              "version": "4.10.8.1108 and earlier versions"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Abhishek Kumar Singh"
        }
      ],
      "datePublic": "2026-08-07T20:05:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash."
            }
          ],
          "value": "SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-07T20:10:19.486Z",
        "orgId": "44b2ff79-1416-4492-88bb-ed0da00c7315",
        "shortName": "sonicwall"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0010"
        }
      ],
      "source": {
        "advisory": "SNWLID-2026-0010",
        "discovery": "EXTERNAL"
      },
      "x_generator": {
        "engine": "Vulnogram 1.0.4"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "44b2ff79-1416-4492-88bb-ed0da00c7315",
    "assignerShortName": "sonicwall",
    "cveId": "CVE-2026-66151",
    "datePublished": "2026-08-07T20:10:19.486Z",
    "dateReserved": "2026-07-24T08:34:11.798Z",
    "dateUpdated": "2026-08-11T19:29:41.797Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}