PT-2020-18272 · Sonicwall · Sonicwall Ssl Vpn+1

Published

2020-09-30

·

Updated

2020-10-07

·

CVE-2020-5132

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SonicWall SSL-VPN products (affected versions not specified) SonicWall firewall SSL-VPN feature (affected versions not specified)
Description The issue is related to a misconfiguration in SonicWall SSL-VPN products and the SonicWall firewall SSL-VPN feature, which can lead to a DNS flaw known as domain name collision vulnerability. This occurs when users publicly display their organization's internal domain names in the SSL-VPN authentication page. An attacker with knowledge of internal domain names can potentially exploit this vulnerability.
Recommendations For SonicWall SSL-VPN products, consider restricting access to the SSL-VPN authentication page to prevent public display of internal domain names until a proper configuration is in place. For SonicWall firewall SSL-VPN feature, restrict the use of the SSL-VPN feature to minimize the risk of exploitation, and review the configuration to ensure internal domain names are not publicly exposed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5132

Affected Products

Sonicwall Ssl Vpn
Sonicwall Firewall