A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0027 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
No history.
Information
Published : 2022-01-10 14:10
Updated : 2022-01-19 13:44
NVD link : CVE-2021-20046
Mitre link : CVE-2021-20046
JSON object : View
Products Affected
sonicwall
- tz670
- tz300
- tz470w
- nsa_5650
- supermassive_e10200
- nsv_200
- supermassive_9200
- soho_250w
- nsa_9250
- tz570
- nsa_6700
- tz300w
- tz400w
- supermassive_9600
- tz570p
- nssp_15700
- nsv_800
- nsv_10
- supermassive_e10400
- tz270
- tz600p
- nsv_1600
- nsv_100
- nsa_4700
- nsv_870
- tz350
- supermassive_9400
- tz400
- tz370w
- tz350w
- nsv_400
- nsv_50
- tz270w
- nsv_470
- nssp_13700
- nsa_2700
- tz500w
- tz570w
- tz600
- nssp_12400
- tz470
- tz500
- nsa_3700
- nsa_3650
- supermassive_e10800
- nsa_9450
- nsa_4650
- soho_250
- nsv_300
- nsa_2650
- supermassive_9800
- nssp_12800
- nsv_25
- nsv_270
- nsa_6650
- nsa_9650
- tz370
- sonicos
- tz300p
CWE
CWE-787
Out-of-bounds Write