2019-12-31 14:01:04 +00:00
{
2020-10-12 11:01:48 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "PSIRT@sonicwall.com" ,
"ID" : "CVE-2020-5138" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "SonicOS" ,
"version" : {
"version_data" : [
{
"version_value" : "SonicOS 6.5.4.7-79n and earlier"
} ,
{
"version_value" : "SonicOS 5.9.1.7-2n and earlier"
} ,
{
"version_value" : "SonicOS 5.9.1.13-5n and earlier"
} ,
{
"version_value" : "SonicOS 6.5.1.11-4n and earlier"
} ,
{
"version_value" : "SonicOS 6.0.5.3-93o and earlier"
} ,
{
"version_value" : "SonicOSv 6.5.4.4-44v-21-794 and earlier"
} ,
{
"version_value" : "SonicOS 7.0.0.0-1"
}
]
}
}
]
2020-10-12 03:33:03 -07:00
} ,
2020-10-12 11:01:48 +00:00
"vendor_name" : "SonicWall"
2020-10-12 03:33:03 -07:00
}
]
}
2020-10-12 11:01:48 +00:00
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0."
}
2020-10-12 03:33:03 -07:00
]
2020-10-12 11:01:48 +00:00
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-122: Heap-based Buffer Overflow"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"name" : "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0013" ,
"refsource" : "CONFIRM" ,
"url" : "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0013"
}
]
}
2019-12-31 14:01:04 +00:00
}