CVE-2020-5132Sensitive Information Exposure in Sma100

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 61.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 24

Description

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

CVEListV5sonicwall/sma100SMA100 10.2.0.2-20sv
CVEListV5sonicwall/sma1000SMA1000 12.4.0-2223
CVEListV5sonicwall/sonicosSonicOS 6.5.4.6-79n
NVDsonicwall/sonicos6.5.4.6-79n
NVDsonicwall/sma100_firmware10.2.0.2-20sv, 12.4.0-2223+1

🔴Vulnerability Details

2
GHSA
GHSA-cm74-jg3x-hghv: SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerabi2022-05-24
CVEList
CVE-2020-5132: SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerabi2020-09-30
CVE-2020-5132 — Sensitive Information Exposure | cvebase