CVE-2020-5135 Details
Description
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
A buffer overflow vulnerability has been identified in SonicWall SonicOS, specifically in Gen 6 versions 6.5.4.7, 6.5.1.12, 6.0.5.3, and SonicOSv 6.5.4.v. This vulnerability allows remote attackers to cause a denial-of-service condition and potentially execute arbitrary code by sending malicious requests to the firewall.
Users can upgrade to SonicOS 6.5.4.7-83n, 6.5.1.12-1n, 6.0.5.3-94o, or SonicOSv 6.5.4.v-21s-987 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5135 | CISA-ADP | US Government Resource |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010 | CVE | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| SonicWall SonicOS Buffer Overflow Vulnerability | Mar 15, 2022 | Apr 5, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sonicwall sonicos | <= 6.0.5.3 >= 6.5.0.0, <= 6.5.1.11 >= 6.5.4.0, <= 6.5.4.7 7.0.0.0 |
CPE
Remediation
| |
| sonicwall sonicosv | <= 6.5.4.4 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 31, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 2, 2025 | Modified Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 3, 2022 | Reanalysis | [email protected] |
| Oct 23, 2020 | Initial Analysis | [email protected] |