CVE-2020-5130

MEDIUM

SonicOS < 6.5.4.4-44n - External Service Interaction via SSLVPN LDAP Login Request

Title source: llm
STIX 2.1

Description

SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0055
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-20
Status published
Products (1)
sonicwall/sonicos < 6.5.4.4-44n
Published Jul 17, 2020
Tracked Since Feb 18, 2026