CVE-2020-5135
KEV ransomwaremassBuffer Overflow in SonicWall SonicOS Enables DoS and Potential RCE on Firewalls
CISA: SonicWall SonicOS Buffer Overflow Vulnerability
CVE-2020-5135 is a buffer overflow vulnerability (CWE-120) in SonicWall's SonicOS firewall operating system. A remote attacker can trigger the flaw by sending a maliciously crafted request to a firewall running SonicOS, which can crash network services and cause a Denial of Service, with potential for arbitrary code execution. Because SonicOS runs on SonicWall perimeter firewalls and remote-access gateways, successful code execution would give an attacker a foothold at the network edge, a high-value position for both DoS and follow-on compromise. Any organization operating a SonicWall firewall running SonicOS is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS estimates a 26.9% probability of exploitation within 30 days (98th percentile), indicating active and elevated exploitation risk even though no public PoC is known.
What to do: Apply updated SonicOS firmware per SonicWall's instructions, as required by the CISA KEV listing, and confirm against SonicWall's advisory which firmware versions fix CVE-2020-5135 for your appliance. Until patched, restrict firewall management and remote-access (SSL-VPN) interfaces to trusted networks rather than the open internet. Given known ransomware use, hunt for signs of exploitation such as firewall crashes/reboots and anomalous outbound or lateral activity.
| SonicWall SonicOS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
- Affected
- SonicWall SonicOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- sonicwall
- Products
- sonicos, sonicosv
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H