SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00484.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Sonicwall
Subscribe
|
Nsa2700
Subscribe
Nsa3700
Subscribe
Nsa4700
Subscribe
Nsa5700
Subscribe
Nsa6700
Subscribe
Nsa 2600
Subscribe
Nsa 2650
Subscribe
Nsa 3600
Subscribe
Nsa 3650
Subscribe
Nsa 4600
Subscribe
Nsa 4650
Subscribe
Nsa 5600
Subscribe
Nsa 5650
Subscribe
Nsa 6600
Subscribe
Nsa 6650
Subscribe
Nssp10700
Subscribe
Nssp11700
Subscribe
Nssp13700
Subscribe
Nssp15700
Subscribe
Nsv10
Subscribe
Nsv100
Subscribe
Nsv1600
Subscribe
Nsv200
Subscribe
Nsv25
Subscribe
Nsv270
Subscribe
Nsv300
Subscribe
Nsv400
Subscribe
Nsv470
Subscribe
Nsv50
Subscribe
Nsv800
Subscribe
Nsv870
Subscribe
Sm 9200
Subscribe
Sm 9250
Subscribe
Sm 9400
Subscribe
Sm 9450
Subscribe
Sm 9600
Subscribe
Sm 9650
Subscribe
Soho 250
Subscribe
Soho 250w
Subscribe
Sohow
Subscribe
Sonicos
Subscribe
Tz270
Subscribe
Tz270w
Subscribe
Tz370
Subscribe
Tz370w
Subscribe
Tz470
Subscribe
Tz470w
Subscribe
Tz570
Subscribe
Tz570p
Subscribe
Tz570w
Subscribe
Tz670
Subscribe
Tz 300
Subscribe
Tz 300p
Subscribe
Tz 300w
Subscribe
Tz 350
Subscribe
Tz 400
Subscribe
Tz 400w
Subscribe
Tz 500
Subscribe
Tz 500w
Subscribe
Tz 600
Subscribe
Tz 600p
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43008 | SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sonicwall
Published:
Updated: 2024-09-13T16:04:35.863Z
Reserved: 2023-07-27T00:07:04.124Z
Link: CVE-2023-39276
Updated: 2024-08-02T18:02:06.830Z
Status : Modified
Published: 2023-10-17T23:15:11.573
Modified: 2024-11-21T08:15:02.593
Link: CVE-2023-39276
No data.
OpenCVE Enrichment
No data.
EUVD