← Vulnerability feed

Vulnerability record · CVE-2020-5135 · published 12 October 2020

CVE-2020-5135: SonicWall SonicOS buffer overflow in firewall request handling

Sonicwall · Sonicos

SonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0, and can cause denial of service with potential arbitrary code execution. The flaw is remotely reachable without authentication, making it a serious perimeter risk.

9.8 CVSS 3.1 Critical CISA KEV since 15 Mar 2022 Known ransomware use EPSS 27% · top 2.0% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
27%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote reachability, CISA KEV listing with known ransomware use, and high EPSS all point to urgent remediation.

What it is

SonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0, and can cause denial of service with potential arbitrary code execution. The flaw is remotely reachable without authentication, making it a serious perimeter risk.

Impact

An unauthenticated remote attacker can crash the firewall, disrupting network protection and connectivity, and may achieve arbitrary code execution on the device. Successful code execution would give the attacker control of a security appliance at the network edge.

Attack surface

Reached over the network by sending a crafted request to the SonicOS firewall; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. Any internet-exposed management or service interface on an affected version is in scope.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with a 2022-04-05 remediation due date and flags known ransomware campaign use. EPSS is 0.26869 (97.9th percentile), and references are vendor advisories plus the CISA KEV entry, indicating real-world exploitation.

What to do

  • Apply the SonicWall vendor updates for the affected SonicOS and SonicOSv versions listed in advisory SNWLID-2020-0010.
  • Restrict management and service interfaces from untrusted networks, especially the public internet, until patching is complete.
  • Segment or isolate affected firewalls and monitor them closely if they cannot be patched immediately.
  • Verify no affected versions remain in inventory and track remediation against the CISA KEV due date.

Detection

  • Monitor firewall and IDS/IPS logs for crashes, restarts or abnormal process termination on SonicOS devices.
  • Alert on unexpected inbound requests to firewall management or service ports from untrusted sources.
  • Hunt for post-exploitation signs such as new or modified accounts, configuration changes, or unexpected outbound connections from the appliance.
  • Correlate device availability gaps with inbound traffic spikes to identify DoS attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-5135 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "SonicWall SonicOS Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5135 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-53704SonicWall SonicOS SSLVPN authentication bypassSonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a C…KEVEPSS 95%analysed9.8CVE-2024-40766SonicWall SonicOS improper access control in management accessSonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash …KEVEPSS 18%analysed9.8CVE-2025-40600Sonicwall sonicos vulnerabilityUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d…EPSS 0.91%9.8CVE-2024-22394Sonicwall sonicos improper authentication vulnerabilityAn improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …EPSS 0.75%9.8CVE-2022-22274SonicOS HTTP request stack buffer overflowSonicOS and SonicOSv contain a stack-based buffer overflow reachable through an HTTP request. A remote unauthenticated attacker can trigger it to cra…EPSS 76%analysed9.8CVE-2019-12260Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…EPSS 23%9.8CVE-2019-12261Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…EPSS 9.0%9.8CVE-2019-12255VxWorks IPNET TCP urgent pointer integer underflow buffer overflowWind River VxWorks contains a buffer overflow in the TCP component of its IPNET network stack, triggered by a TCP Urgent Pointer value of 0 that caus…EPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2020-5135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.