SonicWall Left a VPN Flaw Partially Unpatched Amidst 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5135 | Buffer Overflow in SonicWall SonicOS Enables DoS and Potential RCE on Firewalls CVE-2020-5135 is a buffer overflow vulnerability (CWE-120) in SonicWall's SonicOS firewall operating system. A remote attacker can trigger the flaw by sending a maliciously crafted request to a firewall running SonicOS, which can crash network services and cause a Denial of Service, with potential for arbitrary code execution. Because SonicOS runs on SonicWall perimeter firewalls and remote-access gateways, successful code execution would give an attacker a foothold at the network edge, a high-value position for both DoS and follow-on compromise. Any organization operating a SonicWall firewall running SonicOS is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS estimates a 26.9% probability of exploitation within 30 days (98th percentile), indicating active and elevated exploitation risk even though no public PoC is known. Do: Apply updated SonicOS firmware per SonicWall's instructions, as required by the CISA KEV listing, and confirm against SonicWall's advisory which firmware versions fix CVE-2020-5135 for your appliance. Until patched, restrict firewall management and remote-access (SSL-VPN) interfaces to trusted networks rather than the open internet. Given known ransomware use, hunt for signs of exploitation such as firewall crashes/reboots and anomalous outbound or lateral activity. | 9.8 | 27% | KEV ransomware |
| mass≈ hundreds of thousands of internet-exposed SonicWall firewalls/remote-access endpoints | |
| CVE-2021-20019 | A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensi A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability. NVD description · AI analysis pending | 7.5 | 1% |
| — |
Full article365 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 23, 2021
A critical vulnerability in SonicWall VPN appliances that was believed to have been patched last year has been now found to be "botched," with the company leaving a memory leak flaw unaddressed, until now, that could permit a remote attacker to gain access to sensitive information.
The shortcoming was rectified in an update rolled out to SonicOS on June 22.
Tracked as CVE-2021-20019 (CVSS score: 5.3), the vulnerability is the consequence of a memory leak when sending a specially-crafted unauthenticated HTTP request, culminating in information disclosure.
It's worth noting that SonicWall's decision to hold back the patch comes amid multiple zero-day disclosures affecting its remote access VPN and email security products that have been exploited in a series of in-the-wild attacks to deploy backdoors and a new strain of ransomware called FIVEHANDS.
Howevere, there is no evidence that the flaw is being exploited in the wild.
![]() |
| Memory Dump PoC |
"SonicWall physical and virtual firewalls running certain versions of SonicOS may contain a vulnerability where the HTTP server response leaks partial memory," SonicWall said in an advisory published Tuesday. "This can potentially lead to an internal sensitive data disclosure vulnerability."
The original flaw, identified as CVE-2020-5135 (CVSS score: 9.4), concerned a buffer overflow vulnerability in SonicOS that could allow a remote attacker to cause denial-of-service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
While SonicWall rolled out a patch in October 2020, additional testing undertaken by cybersecurity firm Tripwire revealed a memory leak as a "result of an improper fix for CVE-2020-5135," according to security researcher Craig Young, who reported the new issue to SonicWall on October 6, 2020.
"As a one- or two-line fix with minimal impact, I had expected that a patch would probably come out quickly but, fast-forward to March and I still had not heard back," Young noted in a write-up on Tuesday. "I reconnected with their PSIRT on March 1, 2021 for an update, but ultimately it took until well into June before an advisory could be released."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/06/sonicwall-left-vpn-flaw-partially.html
