PT-2020-6391 · Sonicwall · Sonicos

Abramov Nikita

+1

·

Published

2020-10-12

·

Updated

2026-06-04

·

CVE-2020-5135

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicOS versions 6.0.5.3 and earlier SonicOS versions 6.5.1.11-4n and earlier SonicOS versions 6.5.4.7-79n and earlier SonicOSv versions 6.5.4.4-44v-21-794 and earlier SonicOS version 7.0.0.0-1
Description A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. The vulnerability is related to a lack of size checking for copied data. This issue can be exploited without logging in.
Recommendations For SonicOS version 6.0.5.3 and earlier, update to a version that includes the fix for this issue. For SonicOS version 6.5.1.11-4n and earlier, update to a version that includes the fix for this issue. For SonicOS version 6.5.4.7-79n and earlier, update to a version that includes the fix for this issue. For SonicOSv version 6.5.4.4-44v-21-794 and earlier, update to a version that includes the fix for this issue. For SonicOS version 7.0.0.0-1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable SonicOS versions until a patch is available.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2021-04552
CVE-2020-5135

Affected Products

Sonicos