SonicWall Gen7 NSv
cpe:2.3:h:sonicwall:nsv_270:*:*:*:*:*:*:*, +2 more
- >= 7.1.1-7040, <= 7.1.3-7015
A null pointer dereference vulnerability has been identified in the SonicOS SSLVPN Virtual Office interface. This vulnerability allows a remote, unauthenticated attacker to crash the firewall, potentially causing a denial-of-service condition. The issue affects SonicWall Gen7 NSv and various Gen7 Firewall models, specifically in the 7.1.x version range, as well as TZ80 users on versions through 8.0.0-8037.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the firewall to crash.
The vulnerability can be mitigated by disabling the SSLVPN service on the firewall. For users on affected versions, upgrading to SonicOS 7.2.0-7015 or higher is recommended. TZ80 users should upgrade to version 8.0.1-8017 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.