PT-2020-18270 · Sonicwall · Sonicos

Published

2020-07-17

·

Updated

2020-07-22

·

CVE-2020-5130

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions SonicOS versions prior to 6.5.4.4-44n
Description The issue is related to improper validation of SonicOS SSLVPN LDAP login requests, allowing remote attackers to cause external service interaction, specifically DNS interaction.
Recommendations For versions prior to 6.5.4.4-44n, update to a version later than 6.5.4.4-44n to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5130

Affected Products

Sonicos