EXPOSURES › CVE-2020-5135
CVE-2020-5135
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote buffer overflow in SonicWall SonicOS allows attackers to execute arbitrary code and cause denial of service.
This vulnerability enables remote code execution, allowing attackers to compromise firewalls and potentially access protected networks. DIB organizations must ensure all SonicWall devices are patched immediately to prevent exploitation and maintain CMMC compliance. The active exploitation status indicates a high risk of compromise in the wild.
Shame score — The vulnerability is actively exploited in the wild, enabling remote code execution on critical network infrastructure, which represents a severe and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.