A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.
📦
tz270
Vendor: sonicwall
Actively Exploited
2
CISA KEV List
PoC / Exploits
5
Code Available
Total RCEs
13
Remote Access
Total CVEs
43
Total Indexed
Avg. EPSS
7.54%
Exploit Prob.
Security Vulnerability Index
Page 4 / 5
8.8
CVSS
CVE-2021-20046
RCE
Severity: HIGH
6.1
CVSS
CVE-2021-20031
Exploit Found
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
Severity: MEDIUM
7.5
CVSS
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls.
Severity: HIGH