Known vulnerabilities in SonicOS 5.9
Vendor:
SonicWall
Software:
SonicOS
Version:
5.9
Software CPE:
cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*
Website:
https://www.sonicwall.com/
Total vulnerabilities:
12
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
8.2.2-8015
7.3.3-7015
8.2.1-8010
6.5.5.2-28n
8.2.0-8009
8.1.0-8017
7.3.2-7010
7.0.1-5169
8.0.3-8011
7.3.1-7013
8.0.2-8011
7.3.0-7012
8.0.1-8017
7.2.0-7015
6.5.4.v-21s-RC2457
6.5.4.4-44v-21-2395
6.5.4.4-44v-21-2457
6.5.4.4-44v-21-2472
8.0.0-8037
7.1.3-7015
7.0.1-5165
6.5.5.1-6n
8.0.0-8035
7.1.2-7019
7.0.1-5161
6.5.4.15-117n
6.5.4.15.116n
6.5.2.8-2n
5.9.2.14-13o
7.0.1-5035
6.5.4.14-109n
5.9.2.14-12o
6.5.4.14-107n
6.5.4.v_21s_RC2395
7.1.1-7051
7.0.1-5151
7.1.1-7047
7.1.1-7040
6.5.4.13-105n
6.5.4.4-44v-21-2340
7.0.1-5145
6.5.4.11-97n
7.0.1-5111
6.5.4.4-44v-21-1551
7.0.1-5083
7.0.1-5095
7.0.1-5051-R2624
7.0.1.0-5051-1511
7.0.1.0-5051-R843
6.5.4.10-95n
7.0.1-5030-R2007
7.0.1.0-5030-1391
7.0.1-5030-R780
6.5.4.9-93n
6.5.4.4-44v-21-1519
7.0.1-5030-HF-R844
7.0.1-5051
7.0.1-5050
-
6.5.4.4-44V-21-1452
6.5.4.9-92n
6.5.4.8
7.0.1-R146
6.5.1.13-1n
7.0.1-5023-1349
7.0.1-5018-R1715
5.9.1.13
6.5.1.12
6.5.4.7
7.0.1-R1262
6.5.4.4-44v-21-1288
7.0.1-R1283
7.0.1-R1282
7.0.1-R1456
7.0.0-R906
7.0.0.376
7.0.1-R1036
7.0.0-R713
6.5.1.12-3n
6.5.4.4-44v-21-955
6.5.4.v_21s-1288
6.5.4.8-89n
7.0.1-R579
5.9.2.13-7n
5.9.2.7-5n
6.5.4.7-83n
7 7.0.0.0-2
6.5.4.v-21s-987
6.0.5.3-94o
6.5.1.12-1n
7.0
6.5
6.0
5.9
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU59236 - Stack-based buffer overflow CVE-2021-20048 |
CWE-121 | High | 6.5.4.4-44V-21-1452, 6.5.4.9-92n | 05.01.2022 |
SB2022010525 |
||
| #VU59235 - Stack-based buffer overflow CVE-2021-20046 |
CWE-121 | High | 6.5.4.9-92n | 05.01.2022 |
SB2022010525 |
||
| #VU57238 - Improper Neutralization of HTTP Headers for Scripting Syntax CVE-2021-20031 |
CWE-644 | Low | 6.5.1.13-1n, 6.5.4.v_21s-1288, 6.5.4.8-89n, 7.0.1-R1456, 7.0.1-5018-R1715, 7.0.1-5023-1349 | 12.10.2021 |
SB2021101206 |
||
| #VU47682 - Exposure of sensitive information to an unauthorized actor CVE-2020-5143 |
CWE-200 | Low | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47683 - Out-of-bounds read CVE-2020-5134 |
CWE-125 | Medium | 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47685 - Memory corruption CVE-2020-5136 |
CWE-119 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47686 - Memory corruption CVE-2020-5137 |
CWE-119 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47687 - Heap-based Buffer Overflow CVE-2020-5138 |
CWE-122 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47688 - Untrusted Pointer Dereference CVE-2020-5139 |
CWE-822 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47689 - Out-of-bounds read CVE-2020-5140 |
CWE-125 | High | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47690 - Improper Control of Interaction Frequency CVE-2020-5141 |
CWE-799 | Medium | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |
||
| #VU47691 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5142 |
CWE-79 | Medium | 5.9.2.7-5n, 5.9.2.13-7n, 6.0.5.3-94o, 6.5.1.12-1n, 6.5.4.v-21s-987, 6.5.4.7-83n, 7 7.0.0.0-2 | 12.10.2020 |
SB2020101601 |