ZeroHour

CVE-2020-5135

KEV ransomwaremass

Buffer Overflow in SonicWall SonicOS Enables DoS and Potential RCE on Firewalls

CISA: SonicWall SonicOS Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
27%p98
Published
()
KEV added
AI analysis

CVE-2020-5135 is a buffer overflow vulnerability (CWE-120) in SonicWall's SonicOS firewall operating system. A remote attacker can trigger the flaw by sending a maliciously crafted request to a firewall running SonicOS, which can crash network services and cause a Denial of Service, with potential for arbitrary code execution. Because SonicOS runs on SonicWall perimeter firewalls and remote-access gateways, successful code execution would give an attacker a foothold at the network edge, a high-value position for both DoS and follow-on compromise. Any organization operating a SonicWall firewall running SonicOS is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS estimates a 26.9% probability of exploitation within 30 days (98th percentile), indicating active and elevated exploitation risk even though no public PoC is known.

What to do: Apply updated SonicOS firmware per SonicWall's instructions, as required by the CISA KEV listing, and confirm against SonicWall's advisory which firmware versions fix CVE-2020-5135 for your appliance. Until patched, restrict firewall management and remote-access (SSL-VPN) interfaces to trusted networks rather than the open internet. Given known ransomware use, hunt for signs of exploitation such as firewall crashes/reboots and anomalous outbound or lateral activity.

Affected
SonicWall SonicOS
Estimated exposure
mass≈ hundreds of thousands of internet-exposed SonicWall firewalls/remote-access endpoints — Public internet scans (e.g., Shodan/Censys) routinely show on the order of hundreds of thousands of SonicWall SonicOS management and SSL-VPN interfaces exposed online, and SonicWall's broad SMB/enterprise installed base makes it one of the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

CISA Known Exploited Vulnerability
Affected
SonicWall SonicOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
sonicos, sonicosv
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news