QID 730427

Date Published: 2022-04-11

QID 730427: SonicWall SONICOS Stack-Based Buffer Overflow Vulnerability (SNWLID-2022-0003)

A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.

Affected Products:

This vulnerability affected SonicOS
SonicOS - 6.5.4.4-44v-21-1452 and earlier
SonicOS - 7.0.1-R579 and earlier
SonicOS - 7.0.1-5050 and earlier
QID Detection Logic(Unauthenticated): This QID checks for the vulnerable version via SNMP "snmp-sysdescr".

Successful exploitation of the vulnerability may allow remote unauthenticated attackers to crash the device or executing code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released the Patch. Please refer to SNWLID-2022-0003
    Vendor References

    CVEs related to QID 730427

    Software Advisories
    Advisory ID Software Component Link
    SNWLID-2022-0003 URL Logo psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003