Description
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- SonicWall / SonicOS6.5.4.4-44v-21-2395 and older versions – 6.5.4.4-44v-21-2395 and older versions
- SonicWall / SonicOS7.0.1-5151 and older versions – 7.0.1-5151 and older versions
- SonicWall / SonicOS7.1.1-7051 and older versions – 7.1.1-7051 and older versions