7.5

CVE-2021-20027

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls.

Data is provided by the National Vulnerability Database (NVD)
SonicwallSonicos Version <= 7.0.1-r1262
   SonicwallNsa 2650 Version-
   SonicwallNsa 2700 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 3700 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 4700 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6650 Version-
   SonicwallNsa 6700 Version-
   SonicwallNsa 9250 Version-
   SonicwallNsa 9450 Version-
   SonicwallNsa 9650 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz300 Version-
   SonicwallTz300p Version-
   SonicwallTz300w Version-
   SonicwallTz350 Version-
   SonicwallTz350w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz400 Version-
   SonicwallTz400w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz500 Version-
   SonicwallTz500w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz600 Version-
   SonicwallTz600p Version-
   SonicwallTz670 Version-
SonicwallSonicos Version <= 7.0.1-r.1219
   SonicwallNsv 10 Version-
   SonicwallNsv 100 Version-
   SonicwallNsv 1600 Version-
   SonicwallNsv 200 Version-
   SonicwallNsv 25 Version-
   SonicwallNsv 270 Version-
   SonicwallNsv 300 Version-
   SonicwallNsv 400 Version-
   SonicwallNsv 470 Version-
   SonicwallNsv 50 Version-
   SonicwallNsv 800 Version-
   SonicwallNsv 870 Version-
SonicwallSonicos Version <= 7.0.1-r514
   SonicwallNssp 12400 Version-
   SonicwallNssp 12800 Version-
   SonicwallNssp 13700 Version-
   SonicwallNssp 15700 Version-
SonicwallSonicos Version <= 5.9.1.13
   SonicwallNsa 2650 Version-
   SonicwallNsa 2700 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 3700 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 4700 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6650 Version-
   SonicwallNsa 6700 Version-
   SonicwallNsa 9250 Version-
   SonicwallNsa 9450 Version-
   SonicwallNsa 9650 Version-
   SonicwallSoho 250 Version-
   SonicwallSoho 250w Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz300 Version-
   SonicwallTz300p Version-
   SonicwallTz300w Version-
   SonicwallTz350 Version-
   SonicwallTz350w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz400 Version-
   SonicwallTz400w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz500 Version-
   SonicwallTz500w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz600 Version-
   SonicwallTz600p Version-
   SonicwallTz670 Version-
SonicwallSonicos Version <= 6.5.1.12
   SonicwallNssp 12400 Version-
   SonicwallNssp 12800 Version-
   SonicwallSupermassive 9800 Version-
SonicwallSonicos Version <= 6.5.4.7
   SonicwallNsa 2650 Version-
   SonicwallNsa 2700 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 3700 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 4700 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6650 Version-
   SonicwallNsa 6700 Version-
   SonicwallNsa 9250 Version-
   SonicwallNsa 9450 Version-
   SonicwallNsa 9650 Version-
   SonicwallSoho 250 Version-
   SonicwallSoho 250w Version-
   SonicwallSupermassive 9200 Version-
   SonicwallSupermassive 9400 Version-
   SonicwallSupermassive 9600 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz300 Version-
   SonicwallTz300p Version-
   SonicwallTz300w Version-
   SonicwallTz350 Version-
   SonicwallTz350w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz400 Version-
   SonicwallTz400w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz500 Version-
   SonicwallTz500w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz600 Version-
   SonicwallTz600p Version-
   SonicwallTz670 Version-
SonicwallSonicos
   SonicwallNsv 10 Version-
   SonicwallNsv 100 Version-
   SonicwallNsv 1600 Version-
   SonicwallNsv 200 Version-
   SonicwallNsv 25 Version-
   SonicwallNsv 270 Version-
   SonicwallNsv 300 Version-
   SonicwallNsv 400 Version-
   SonicwallNsv 470 Version-
   SonicwallNsv 50 Version-
   SonicwallNsv 800 Version-
   SonicwallNsv 870 Version-
SonicwallSonicos Version <= 6.0.5.3-94o
   SonicwallSupermassive E10200 Version-
   SonicwallSupermassive E10400 Version-
   SonicwallSupermassive E10800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.62
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.