Description
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.
Published: 2022-01-07
Score: 8.8 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-7511 A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.
History

No history.

Subscriptions

Sonicwall Nsa 2650 Nsa 2700 Nsa 3650 Nsa 3700 Nsa 4650 Nsa 4700 Nsa 5650 Nsa 6650 Nsa 6700 Nsa 9250 Nsa 9450 Nsa 9650 Nssp 12400 Nssp 12800 Nssp 13700 Nssp 15700 Nsv 10 Nsv 100 Nsv 1600 Nsv 200 Nsv 25 Nsv 270 Nsv 300 Nsv 400 Nsv 470 Nsv 50 Nsv 800 Nsv 870 Soho 250 Soho 250w Sonicos Supermassive 9200 Supermassive 9400 Supermassive 9600 Supermassive 9800 Supermassive E10200 Supermassive E10400 Supermassive E10800 Tz270 Tz270w Tz300 Tz300p Tz300w Tz350 Tz350w Tz370 Tz370w Tz400 Tz400w Tz470 Tz470w Tz500 Tz500w Tz570 Tz570p Tz570w Tz600 Tz600p Tz670
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2024-08-03T17:30:06.959Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-10T14:10:16.610

Modified: 2024-11-21T05:45:51.193

Link: CVE-2021-20048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses