SonicWall SonicOS
cpe:2.3:o:dell:sonicwall_sonicos:*:*:*:*:*:*:*, +2 more
- <= 6.5.4.4-44v-21-2395
A buffer overflow vulnerability has been identified in SonicWall SonicOS through IPSec, specifically in versions 6.5.4.4-44v-21-2395 and earlier, as well as in several Gen7 models. This vulnerability allows remote attackers, under certain conditions, to cause a denial-of-service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. The issue arises from an integer-based buffer overflow, which can be exploited to manipulate memory and execute unauthorized code.
Exploitation of this vulnerability can lead to a denial-of-service condition and potentially allow for arbitrary code execution on the affected device.
Users can upgrade to SonicOS versions 6.5.4.v-21s-RC2457 and higher for Gen6 NSv platforms, or to versions 7.0.1-5165 and higher or 7.1.3-7015 and higher for Gen7 models, depending on their specific device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.