Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-20046


A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.


Published

2022-01-10T14:10:16.537

Last Modified

2024-11-21T05:45:50.900

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-121
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sonicwall sonicos ≤ 7.0.1-r146 Yes
Hardware sonicwall nsa_2650 - No
Hardware sonicwall nsa_2700 - No
Hardware sonicwall nsa_3650 - No
Hardware sonicwall nsa_3700 - No
Hardware sonicwall nsa_4650 - No
Hardware sonicwall nsa_4700 - No
Hardware sonicwall nsa_5650 - No
Hardware sonicwall nsa_6650 - No
Hardware sonicwall nsa_6700 - No
Hardware sonicwall nsa_9250 - No
Hardware sonicwall nsa_9450 - No
Hardware sonicwall nsa_9650 - No
Hardware sonicwall tz270 - No
Hardware sonicwall tz270w - No
Hardware sonicwall tz300 - No
Hardware sonicwall tz300p - No
Hardware sonicwall tz300w - No
Hardware sonicwall tz350 - No
Hardware sonicwall tz350w - No
Hardware sonicwall tz370 - No
Hardware sonicwall tz370w - No
Hardware sonicwall tz400 - No
Hardware sonicwall tz400w - No
Hardware sonicwall tz470 - No
Hardware sonicwall tz470w - No
Hardware sonicwall tz500 - No
Hardware sonicwall tz500w - No
Hardware sonicwall tz570 - No
Hardware sonicwall tz570p - No
Hardware sonicwall tz570w - No
Hardware sonicwall tz600 - No
Hardware sonicwall tz600p - No
Hardware sonicwall tz670 - No
Operating System sonicwall sonicos ≤ 7.0.1-5023-1349 Yes
Hardware sonicwall nsv_10 - No
Hardware sonicwall nsv_100 - No
Hardware sonicwall nsv_1600 - No
Hardware sonicwall nsv_200 - No
Hardware sonicwall nsv_25 - No
Hardware sonicwall nsv_270 - No
Hardware sonicwall nsv_300 - No
Hardware sonicwall nsv_400 - No
Hardware sonicwall nsv_470 - No
Hardware sonicwall nsv_50 - No
Hardware sonicwall nsv_800 - No
Hardware sonicwall nsv_870 - No
Operating System sonicwall sonicos ≤ 7.0.1-5018-r1715 Yes
Hardware sonicwall nssp_12400 - No
Hardware sonicwall nssp_12800 - No
Hardware sonicwall nssp_13700 - No
Hardware sonicwall nssp_15700 - No
Operating System sonicwall sonicos ≤ 6.5.4.8-89n Yes
Hardware sonicwall nsa_2650 - No
Hardware sonicwall nsa_2700 - No
Hardware sonicwall nsa_3650 - No
Hardware sonicwall nsa_3700 - No
Hardware sonicwall nsa_4650 - No
Hardware sonicwall nsa_4700 - No
Hardware sonicwall nsa_5650 - No
Hardware sonicwall nsa_6650 - No
Hardware sonicwall nsa_6700 - No
Hardware sonicwall nsa_9250 - No
Hardware sonicwall nsa_9450 - No
Hardware sonicwall nsa_9650 - No
Hardware sonicwall soho_250w - No
Hardware sonicwall supermassive_9200 - No
Hardware sonicwall supermassive_9400 - No
Hardware sonicwall supermassive_9600 - No
Hardware sonicwall supermassive_9800 - No
Hardware sonicwall tz270 - No
Hardware sonicwall tz270w - No
Hardware sonicwall tz300 - No
Hardware sonicwall tz300p - No
Hardware sonicwall tz300w - No
Hardware sonicwall tz350 - No
Hardware sonicwall tz350w - No
Hardware sonicwall tz370 - No
Hardware sonicwall tz370w - No
Hardware sonicwall tz400 - No
Hardware sonicwall tz400w - No
Hardware sonicwall tz470 - No
Hardware sonicwall tz470w - No
Hardware sonicwall tz500 - No
Hardware sonicwall tz500w - No
Hardware sonicwall tz570 - No
Hardware sonicwall tz570p - No
Hardware sonicwall tz570w - No
Hardware sonicwall tz600 - No
Hardware sonicwall tz600p - No
Hardware sonicwall tz670 - No
Operating System sonicwall sonicos ≤ 6.5.1.13-1n Yes
Hardware sonicwall nssp_12400 - No
Hardware sonicwall nssp_12800 - No
Hardware sonicwall supermassive_9800 - No
Operating System sonicwall sonicos ≤ 6.0.5.3-94o Yes
Hardware sonicwall supermassive_e10200 - No
Hardware sonicwall supermassive_e10400 - No
Hardware sonicwall supermassive_e10800 - No
Operating System sonicwall sonicos ≤ 5.9.1.13 Yes
Hardware sonicwall nsa_2650 - No
Hardware sonicwall nsa_2700 - No
Hardware sonicwall nsa_3650 - No
Hardware sonicwall nsa_3700 - No
Hardware sonicwall nsa_4650 - No
Hardware sonicwall nsa_4700 - No
Hardware sonicwall nsa_5650 - No
Hardware sonicwall nsa_6650 - No
Hardware sonicwall nsa_6700 - No
Hardware sonicwall nsa_9250 - No
Hardware sonicwall nsa_9450 - No
Hardware sonicwall nsa_9650 - No
Hardware sonicwall soho_250 - No
Hardware sonicwall soho_250w - No
Hardware sonicwall tz270 - No
Hardware sonicwall tz270w - No
Hardware sonicwall tz300 - No
Hardware sonicwall tz300p - No
Hardware sonicwall tz300w - No
Hardware sonicwall tz350 - No
Hardware sonicwall tz350w - No
Hardware sonicwall tz370 - No
Hardware sonicwall tz370w - No
Hardware sonicwall tz400 - No
Hardware sonicwall tz400w - No
Hardware sonicwall tz470 - No
Hardware sonicwall tz470w - No
Hardware sonicwall tz500 - No
Hardware sonicwall tz500w - No

References