CVE-2020-5132: Infoleak
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5132?
CVE-2020-5132 refers to a vulnerability in SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature known as domain name collision vulnerability.
What is the severity of CVE-2020-5132?
CVE-2020-5132 has a severity rating of 5.3, which is considered medium.
Which software is affected by CVE-2020-5132?
Sonicwall Sma100 Firmware versions 10.2.0.2-20sv and 12.4.0-2223, as well as SonicWall SonicOS version 6.5.4.6-79n, are affected by CVE-2020-5132.
What is the impact of CVE-2020-5132?
CVE-2020-5132 allows an attacker with knowledge of internal domain names displayed in the SSL-VPN authentication page to exploit a DNS flaw.
Is SonicWall SMA100 affected by CVE-2020-5132?
No, SonicWall SMA100 is not affected by CVE-2020-5132.