#VU47684 Buffer overflow in SonicOS - CVE-2020-5135

 

#VU47684 Buffer overflow in SonicOS - CVE-2020-5135

Published: October 12, 2020 / Updated: March 16, 2022


Vulnerability identifier: #VU47684
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2020-5135
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
SonicOS
Software vendor:
SonicWall

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing requests. A remote non-authenticated attacker can send specially crafted request to the system, trigger memory corruption and crash the firewall or execute arbitrary code on the system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links