Lucene search

K
nvd[email protected]NVD:CVE-2023-39277
HistoryOct 17, 2023 - 11:15 p.m.

CVE-2023-39277

2023-10-1723:15:11
CWE-121
CWE-787
web.nvd.nist.gov
sonicos
stack overflow
buffer overflow
sonicflow.csv
appflowsessions.csv
firewall crash
vulnerability

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.

Affected configurations

NVD
Node
sonicwallsonicosRange<7.0.1-5145
AND
sonicwallnsa2700Match-
OR
sonicwallnsa3700Match-
OR
sonicwallnsa4700Match-
OR
sonicwallnsa5700Match-
OR
sonicwallnsa6700Match-
OR
sonicwallnssp10700Match-
OR
sonicwallnssp11700Match-
OR
sonicwallnssp13700Match-
OR
sonicwallnssp15700Match-
OR
sonicwallnsv10Match-
OR
sonicwallnsv100Match-
OR
sonicwallnsv1600Match-
OR
sonicwallnsv200Match-
OR
sonicwallnsv25Match-
OR
sonicwallnsv270Match-
OR
sonicwallnsv300Match-
OR
sonicwallnsv400Match-
OR
sonicwallnsv470Match-
OR
sonicwallnsv50Match-
OR
sonicwallnsv800Match-
OR
sonicwallnsv870Match-
OR
sonicwalltz270Match-
OR
sonicwalltz270wMatch-
OR
sonicwalltz370Match-
OR
sonicwalltz370wMatch-
OR
sonicwalltz470Match-
OR
sonicwalltz470wMatch-
OR
sonicwalltz570Match-
OR
sonicwalltz570pMatch-
OR
sonicwalltz570wMatch-
OR
sonicwalltz670Match-
Node
sonicwallsonicosRange<6.5.4.4-44v-21-2340
AND
sonicwallnsv10Match-
OR
sonicwallnsv100Match-
OR
sonicwallnsv1600Match-
OR
sonicwallnsv200Match-
OR
sonicwallnsv25Match-
OR
sonicwallnsv270Match-
OR
sonicwallnsv300Match-
OR
sonicwallnsv400Match-
OR
sonicwallnsv470Match-
OR
sonicwallnsv50Match-
OR
sonicwallnsv800Match-
OR
sonicwallnsv870Match-
Node
sonicwallsonicosRange<6.5.4.13-105n
AND
sonicwallnsa_2600Match-
OR
sonicwallnsa_2650Match-
OR
sonicwallnsa_3600Match-
OR
sonicwallnsa_3650Match-
OR
sonicwallnsa_4600Match-
OR
sonicwallnsa_4650Match-
OR
sonicwallnsa_5600Match-
OR
sonicwallnsa_5650Match-
OR
sonicwallnsa_6600Match-
OR
sonicwallnsa_6650Match-
OR
sonicwallsm_9200Match-
OR
sonicwallsm_9250Match-
OR
sonicwallsm_9400Match-
OR
sonicwallsm_9450Match-
OR
sonicwallsm_9600Match-
OR
sonicwallsm_9650Match-
OR
sonicwallsoho_250Match-
OR
sonicwallsoho_250wMatch-
OR
sonicwallsohowMatch-
OR
sonicwalltz_300Match-
OR
sonicwalltz_300pMatch-
OR
sonicwalltz_300wMatch-
OR
sonicwalltz_350Match-
OR
sonicwalltz_400Match-
OR
sonicwalltz_400wMatch-
OR
sonicwalltz_500Match-
OR
sonicwalltz_500wMatch-
OR
sonicwalltz_600Match-
OR
sonicwalltz_600pMatch-

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

Related for NVD:CVE-2023-39277