QID 730766
Date Published: 2023-06-22
QID 730766: SonicWall SONICOS Stack-Based Buffer Overflow Vulnerability (SNWLID-2023-0004)
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
Affected Products:
This vulnerability affected SonicOS
SonicOS - 7.0.1-5095 and earlier versions
SonicOS - 7.0.1-5083 and earlier versions
SonicOS - 6.5.4.4-44v-21-1551 and earlier versions
QID Detection Logic(Unauthenticated):
This QID checks for the vulnerable version via SNMP "snmp-sysdescr".
Successful exploitation of the vulnerability may allow remote unauthenticated attackers to crash the device or executing code.
Solution
Vendor has released the Patch. Please refer to SNWLID-2023-0004
Vendor References
- SNWLID-2023-0004 -
psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004
CVEs related to QID 730766
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SNWLID-2023-0004 |
|