Junglewise Threat Intelligence

CVE-2020-5135: SonicWall SonicOS Buffer Overflow Vulnerability

CVE-2020-5135 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-15

Technologies: SonicWall SonicOS. Vendors: SonicWall.

Executive brief

A stack-based buffer overflow vulnerability in SonicWall SonicOS allows a remote unauthenticated attacker to cause a Denial of Service (DoS) or potentially execute arbitrary code. The flaw is triggered by sending a specially crafted malicious request to the firewall's management interface.

Affected products

  • SonicWall SonicOS 6.0.5.3, 6.5.1.12, 6.5.4.7, 7.0.0.0
  • SonicWall SonicOSv 6.5.4.v

Timeline

  • 2020-10-12: disclosed: NVD Published Date
  • 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-05: patched: CISA due date for applying vendor updates

Related threats