QID 730122

Date Published: 2021-06-24

QID 730122: SonicWall SONICOS Buffer Overflow Vulnerability (SNWLID-2021-0006)

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

Affected Products:

SonicOS - 6.5.4.7-83n
SonicOSv - 6.5.4.4-44v-21-955
SonicOS - 6.5.1.12-3n
SonicOS - 6.0.5.3-94o
SonicOS - 7.0.0-R713 and earlier
SonicOS - 7.0.1-R1036 and earlier
and below SonicOS - 7.0.0.376

QID Detection Logic(Unauthenticated): This QID checks for the vulnerable version via SNMP "snmp-sysdescr".

Successful exploitation of the vulnerability may lead to internal sensitive data disclosure.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released the Patch. Please refer to SNWLID-2021-0006
    Vendor References

    CVEs related to QID 730122

    Software Advisories
    Advisory ID Software Component Link
    SNWLID-2021-0006 URL Logo psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0006