Vulnerability record · CVE-2020-5135 · published 12 October 2020
CVE-2020-5135: SonicWall SonicOS buffer overflow in firewall request handling
Sonicwall · Sonicos
SonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0, and can cause denial of service with potential arbitrary code execution. The flaw is remotely reachable without authentication, making it a serious perimeter risk.
Description
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote reachability, CISA KEV listing with known ransomware use, and high EPSS all point to urgent remediation.
What it is
SonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0, and can cause denial of service with potential arbitrary code execution. The flaw is remotely reachable without authentication, making it a serious perimeter risk.
Impact
An unauthenticated remote attacker can crash the firewall, disrupting network protection and connectivity, and may achieve arbitrary code execution on the device. Successful code execution would give the attacker control of a security appliance at the network edge.
Attack surface
Reached over the network by sending a crafted request to the SonicOS firewall; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. Any internet-exposed management or service interface on an affected version is in scope.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with a 2022-04-05 remediation due date and flags known ransomware campaign use. EPSS is 0.26869 (97.9th percentile), and references are vendor advisories plus the CISA KEV entry, indicating real-world exploitation.
What to do
- Apply the SonicWall vendor updates for the affected SonicOS and SonicOSv versions listed in advisory SNWLID-2020-0010.
- Restrict management and service interfaces from untrusted networks, especially the public internet, until patching is complete.
- Segment or isolate affected firewalls and monitor them closely if they cannot be patched immediately.
- Verify no affected versions remain in inventory and track remediation against the CISA KEV due date.
Detection
- Monitor firewall and IDS/IPS logs for crashes, restarts or abnormal process termination on SonicOS devices.
- Alert on unexpected inbound requests to firewall management or service ports from untrusted sources.
- Hunt for post-exploitation signs such as new or modified accounts, configuration changes, or unexpected outbound connections from the appliance.
- Correlate device availability gaps with inbound traffic spikes to identify DoS attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-5135 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "SonicWall SonicOS Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0010 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5135 | US Government Resource |
Track CVE-2020-5135 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.