← back
CVE-2020-5135

CVE-2020-5135

CVSS 9.8 CRITICALEPSS 26.9%● KEVCWE-120
In short

A buffer overflow flaw in SonicOS firewalls allows attackers to crash the device or potentially run malicious code by sending specially crafted network requests. This affects multiple versions of SonicOS Gen 6 and Gen 7.

Technical detail

CWE-120 buffer overflow in SonicOS enables remote code execution or denial of service via malformed network requests to the firewall, with no authentication required. The vulnerability impacts SonicOS Gen 6 (versions 6.5.4.7, 6.5.1.12, 6.0.5.3, 6.5.4.v) and Gen 7 (7.0.0.0), presenting critical risk to exposed firewall instances.

Summary generated and translated by AI from the official description.
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SonicWall · SonicOS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →