First published: Fri Jul 17 2020(Updated: )
SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | <=6.5.4.4-44n |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-5130.
The title of the vulnerability is 'SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS…'.
The vulnerability allows remote attackers to cause external service interaction (DNS).
SonicOS version 6.5.4.4-44n and earlier are affected.
The severity of the vulnerability is medium (CVSS score: 5.3).
Update SonicOS to version 6.5.4.4-45n or later to fix this vulnerability.
More information about this vulnerability can be found at <a href='https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0003'>this link</a>.