// For flags

CVE-2020-5132

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

Los productos SonicWall SSL-VPN y una configuración inapropiada de la funcionalidad SSL-VPN del firewall SonicWall, conlleva a un posible fallo de DNS conocido como vulnerabilidad de colisión de nombres de dominio. Cuando los usuarios muestran públicamente los nombres de dominio internos de su organización en la página de autenticación SSL-VPN, un atacante con conocimiento de los nombres de dominio internos puede potencialmente aprovecharse de esta vulnerabilidad

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-12-31 CVE Reserved
  • 2020-09-30 CVE Published
  • 2023-06-16 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sonicwall
Search vendor "Sonicwall"
Sma100 Firmware
Search vendor "Sonicwall" for product "Sma100 Firmware"
10.2.0.2-20sv
Search vendor "Sonicwall" for product "Sma100 Firmware" and version "10.2.0.2-20sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma100
Search vendor "Sonicwall" for product "Sma100"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma100 Firmware
Search vendor "Sonicwall" for product "Sma100 Firmware"
12.4.0-2223
Search vendor "Sonicwall" for product "Sma100 Firmware" and version "12.4.0-2223"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma100
Search vendor "Sonicwall" for product "Sma100"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sonicos
Search vendor "Sonicwall" for product "Sonicos"
6.5.4.6-79n
Search vendor "Sonicwall" for product "Sonicos" and version "6.5.4.6-79n"
-
Affected