{"record":"SonicWall evidence record","url":"https://nexalign.io/vendors/sonicwall","vendor":{"slug":"sonicwall","name":"SonicWall","domain":"sonicwall.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-18T04:17:20.316Z","coverage":{"earliest":"2021-11-03T00:00:00.000Z","latest":"2026-07-18T04:17:20.316Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":73,"kindsOfSource":6,"attributedAdvisories":60,"knownExploited":8,"registerEntriesNotAttributable":1,"practitionerThreads":6,"independentItems":5,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":28,"latest":"2026-07-14T19:43:03.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":26,"latest":"2026-07-15T10:11:40.869Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":8,"latest":"2025-12-17T00:00:00.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":5,"latest":"2025-10-12T12:20:03.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":5,"latest":"2026-07-18T04:17:20.316Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2026-02-24T17:23:22.000Z"}],"advisories":{"shown":6,"total":60,"truncated":true,"fullList":"https://nexalign.io/vendors/sonicwall/advisories","items":[{"id":"CVE-2025-40602","description":"SonicWall SMA1000 Missing Authorization Vulnerability","severity":"critical","cvss":6.6,"knownExploited":true,"date":"2025-12-18T10:58:41.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204255","https://nvd.nist.gov/vuln/detail/CVE-2025-40602"]},{"id":"CVE-2024-40766","description":"SonicWall SonicOS Improper Access Control Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2024-09-09T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2024-40766"]},{"id":"CVE-2019-7483","description":"SonicWall SMA100 Directory Traversal Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2022-03-28T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2019-7483"]},{"id":"CVE-2021-20022","description":"SonicWall Email Security Unrestricted Upload of File Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2021-20022"]},{"id":"CVE-2021-20023","description":"SonicWall Email Security Path Traversal Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2021-20023"]},{"id":"CVE-2021-20021","description":"SonicWall Email Security Improper Privilege Management Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2021-20021"]}]},"practitionerThreads":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Marquis sues firewall provider SonicWall, alleges security failings with its firewall backup led to ransomware attack","context":"r/msp","url":"https://www.reddit.com/r/msp/comments/1rdmg8q/marquis_sues_firewall_provider_sonicwall_alleges/","date":"2026-02-24T17:23:22.000Z"},{"title":"SonicWall confirms all Cloud Backup Service users were compromised","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45557682","date":"2025-10-12T12:20:03.000Z"},{"title":"Data leak at Sonicwall: All cloud backups of firewalls stolen","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45543433","date":"2025-10-10T20:29:35.000Z"},{"title":"Akira still bypassing SonicWall SSL VPNs, even with MFA deployed","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45437329","date":"2025-10-01T13:15:21.000Z"},{"title":"Google finds custom backdoor being installed on SonicWall network devices","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44591868","date":"2025-07-17T10:58:07.000Z"}]},"independentCoverage":{"shown":5,"total":5,"truncated":false,"items":[{"title":"SonicWall NSa Series Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/network-firewalls/vendor/sonic-wall/product/sonicwall-network-security-appliance","date":null},{"title":"SonicWall Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/network-firewalls/vendor/sonic-wall","date":null},{"title":"SonicWall - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/SonicWall","date":null},{"title":"SonicWall NSa Series Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/network-firewalls/vendor/sonic-wall/product/sonicwall-network-security-appliance","date":null},{"title":"SonicWall Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/hybrid-mesh-firewall/vendor/sonic-wall","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 1 register entries mention SonicWall without naming a product of SonicWall as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}