First published: Thu Mar 02 2023(Updated: )
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | <=7.0.1-5111 | |
Sonicwall Nsa 2700 | ||
Sonicwall Nsa 3700 | ||
Sonicwall Nsa 4700 | ||
Sonicwall Nsa 5700 | ||
Sonicwall Nsa 6700 | ||
Sonicwall Nssp 10700 | ||
Sonicwall Nssp 11700 | ||
Sonicwall Nssp 13700 | ||
Sonicwall Nsv 270 | ||
Sonicwall Nsv 470 | ||
Sonicwall Nsv 870 | ||
Sonicwall Tz270 | ||
Sonicwall Tz270w | ||
Sonicwall Tz370 | ||
Sonicwall Tz370w | ||
Sonicwall Tz470 | ||
Sonicwall Tz470w | ||
Sonicwall Tz570 | ||
Sonicwall Tz570p | ||
Sonicwall Tz570w | ||
Sonicwall Tz670 | ||
SonicWall SonicOS | <=7.0.1-5083 | |
Sonicwall Nssp 15700 | ||
SonicWall SonicOS | <=6.5.4.4-44v-21-1551 | |
Sonicwall Nsv 10 | ||
Sonicwall Nsv 100 | ||
Sonicwall Nsv 1600 | ||
Sonicwall Nsv 200 | ||
Sonicwall Nsv 25 | ||
Sonicwall Nsv 300 | ||
Sonicwall Nsv 400 | ||
Sonicwall Nsv 50 | ||
Sonicwall Nsv 800 | ||
SonicWall next-generation firewall (NGFW) | =series 6 | |
SonicWall next-generation firewall (NGFW) | =series 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0656 is a stack-based buffer overflow vulnerability in SonicOS.
A remote unauthenticated attacker can exploit CVE-2023-0656 to cause a Denial of Service (DoS), potentially crashing the affected firewall.
SonicOS version 7.0.1-5111 is affected by CVE-2023-0656.
The severity of CVE-2023-0656 is high, with a CVSS score of 7.5.
More information about CVE-2023-0656 can be found at the following reference: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004