LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-5135: SonicWall SonicOS Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-5135 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

CVE-2020-5135 is a buffer overflow vulnerability in SonicWall SonicOS, the operating system used on SonicWall firewalls. A remote attacker can send a malicious request to the device and trigger denial of service, with the potential to execute arbitrary code. Because these appliances commonly sit at the network edge, successful abuse can disrupt traffic or give an attacker a foothold on a critical security control. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-120, a classic buffer overflow. In this class of flaw, the software copies incoming data into a fixed-size memory buffer without adequately checking the length. When an attacker supplies a specially crafted request that exceeds the buffer’s capacity, adjacent memory can be overwritten. On a firewall running SonicOS, that overwrite can crash the process (producing a denial-of-service condition) or, under the right circumstances, allow the attacker to redirect execution flow and run code of their choosing. The CISA summary states that the malicious request is sent directly to the firewall; no further exploit mechanics are provided here, so defenders should treat any unauthenticated or lightly authenticated management or service interface as a potential attack surface and verify exact preconditions in the vendor advisory.

Am I affected? How to find it in your systems

SonicWall SonicOS runs on SonicWall firewall and security appliances that are typically deployed at internet perimeters, in DMZs, or as VPN concentrators. To determine exposure:

Because public detail on precise vulnerable builds is limited to the advisory, always cross-check rather than relying on secondary sources.

How to remediate

The primary action is to apply the updates supplied by SonicWall, following the instructions in the vendor advisory. CISA likewise directs organizations to apply updates per vendor instructions. After patching:

If you can't patch immediately

When immediate firmware installation is not feasible, apply compensating controls to lower risk:

These measures do not eliminate the vulnerability; they only buy time until the vendor update is installed.

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to broader compromises, even when ransomware use has not been documented for this specific CVE. If you suspect the firewall was targeted, examine adjacent systems for signs of lateral movement, rotate credentials that traversed the device, and review network flows for unusual destinations. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SonicOS
WeaknessCWE-120
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities