CVE-2020-5143: Medium severity sonicwall sonicos vulnerability
Published Oct 12, 2020
·Updated
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.
Affected Software
6 affected components
SonicWall SonicOS<=5.9.1.13
SonicWall SonicOS>=6.0.0.0<=6.0.5.3
SonicWall SonicOS>=6.5.0.0<=6.5.1.11
SonicWall SonicOS>=6.5.4.0<=6.5.4.7
SonicWall SonicOS=7.0.0.0
SonicWall SonicOSv<=6.5.4.4
Event History
Oct 12, 2020
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SonicOS SSLVPN vulnerability?
The vulnerability ID for this SonicOS SSLVPN vulnerability is CVE-2020-5143.
2
What is the severity rating of CVE-2020-5143?
The severity rating of CVE-2020-5143 is medium (5.3).
3
How does this vulnerability affect SonicOS Gen 5?
This vulnerability affects SonicOS Gen 5 versions 5.9.1.7 and 5.9.1.13.
4
Which versions of SonicOS Gen 6 are affected by this vulnerability?
This vulnerability affects SonicOS Gen 6 versions 6.0.5.3, 6.5.4.7, and 6.5.1.12.
5
Is SonicOSv affected by this vulnerability?
Yes, SonicOSv version 6.5.4.v is affected by this vulnerability.