SONICWALL VPN VULNERABLE TO RCE BUG IN SONICOS
10/20/2020

Nearly 800,000 VPNs around the world need urgent patching after vendor (Dell SonicWall) issued a security update for a critical flaw last week.

OVERVIEW

  • Security Researchers from Tripwire found the stack-based buffer overflow vulnerability in SonicOS (CVE-2020-5135) a critical bug, with a rating of 9.4 out of 10, and is expected to come under active exploitation once proof-of-concept code is made publicly available

  •  Exploiting the vulnerability doesn't require the attacker to have valid credentials as the bug manifests before any authentication operations.

 

SonicWall